CVE-2026-43606
Last modified
CVE-2026-43606 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially perform timing analysis or electromagnetic emanation attacks, resulting in high confidentiality and integrity impact due to the exposure of private cryptographic keys..
Description
Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially perform timing analysis or electromagnetic emanation attacks, resulting in high confidentiality and integrity impact due to the exposure of private cryptographic keys.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| AMD | Vitis™ Libraries - Security Module | All versions |
| AMD | Vitis™ Unified Installer for FPGAs & Adaptive SoCs in Windows | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-43606?
How severe is CVE-2026-43606?
How do I fix CVE-2026-43606?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-43582OpenClaw before 2026.4.10 contains a server-side request for…6.3
- CVE-2026-43583OpenClaw versions 2026.4.10 before 2026.4.14 fail to persist…6.5
- CVE-2026-43584OpenClaw before 2026.4.10 contains an insufficient environme…8.8
- CVE-2026-43585OpenClaw before 2026.4.15 captures resolved bearer-auth conf…9.8
- CVE-2026-4359A compromised third party cloud server or man-in-the-middle …3.7
- CVE-2026-4360In the Tarfile.extract() function, the filter parameter is n…5.3
- CVE-2026-43616Detect-It-Easy prior to 3.21 contains a path traversal vulne…7.8
- CVE-2026-43617Rsync version 3.4.2 and prior contain an authorization bypas…6.3
- CVE-2026-43618Rsync version 3.4.2 and prior contain an integer overflow vu…8.1
- CVE-2026-43619Rsync version 3.4.2 and prior contain symlink race condition…7.2
- CVE-2026-4362The ElementsKit Elementor Addons plugin for WordPress is vul…6.5
- CVE-2026-43620Rsync version 3.4.2 and prior contain a receiver-side out-of…5.5
Are you affected by CVE-2026-43606?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
