CVE-2026-2815
Awaiting Analysis Awaiting Analysis - Queue
Predictable Key Generation in EFR32xG27 via PUF Misuse

Publication date: 2026-06-25

Last updated on: 2026-06-25

Assigner: Silicon Graphics (SGI)

Description
Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-25
Last Modified
2026-06-25
Generated
2026-06-25
AI Q&A
2026-06-25
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
silicon_labs simplicity_sdk *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-339 A Pseudo-Random Number Generator (PRNG) uses a relatively small seed space, which makes it more susceptible to brute force attacks.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability involves the incorrect use of the Physically Unclonable Function (PUF) key for generating user keys in the EFR32xG27 device series. Due to this incorrect usage, the keys generated become predictable rather than random or unique as intended.

Impact Analysis

Because the user keys generated are predictable, an attacker could potentially guess or reproduce these keys. This compromises the security of cryptographic operations relying on these keys, potentially allowing unauthorized access, data breaches, or other security failures in systems using the affected devices.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-2815. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart