CVE-2026-6923: Nuvoton - CWE-1300: Improper Protection of Physical Side Channels
A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie-Hellman (ECDH) key.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nuvotonto a version that resolves this vulnerability.Fixed in 7.2.4.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6923?
CVE-2026-6923 has a high severity rating due to the risk of key extraction through physical side-channel attacks.
How do I fix CVE-2026-6923?
To mitigate CVE-2026-6923, implement enhanced physical security measures around the Trusted Platform Module (TPM) to prevent unauthorized access.
What specific hardware is affected by CVE-2026-6923?
CVE-2026-6923 affects the Nuvoton Trusted Platform Module (TPM) hardware.
What kind of attack does CVE-2026-6923 involve?
CVE-2026-6923 involves a side-channel attack that requires physical presence to extract ECDH keys.
Who should be concerned about CVE-2026-6923?
Organizations using Nuvoton Trusted Platform Modules should be concerned about CVE-2026-6923 due to the potential for key compromise.