CVE-2026-18349
Received Received - Intake

Hardware Fault Injection in Microchip SAMA5D4

Vulnerability report for CVE-2026-18349, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: Microchip Technology

Description

Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Hardware Fault Injection. This issue affects SAMA5D4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
microchip sama5d4 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1247 The device does not contain or contains incorrectly implemented circuitry or sensors to detect and mitigate voltage and clock glitches and protect sensitive information or software contained on the device.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper protection against voltage and clock glitches in Microchip SAMA5D4 hardware. It allows hardware fault injection, which could enable an attacker to manipulate the device's operation by altering voltage or timing signals.

Detection Guidance

Detection of hardware fault injection vulnerabilities like CVE-2026-18349 typically requires specialized hardware and expertise. There are no standard software commands to detect this issue directly. Monitoring for unusual voltage fluctuations or clock anomalies may require oscilloscopes or logic analyzers. Consult hardware security guidelines for Microchip SAMA5D4 devices.

Impact Analysis

An attacker could exploit this to cause incorrect behavior in the SAMA5D4 device, potentially leading to unauthorized access, data corruption, or system crashes. Since the device is used in embedded systems, this could affect critical operations in industrial, automotive, or IoT applications.

Compliance Impact

This vulnerability involves improper protection against voltage and clock glitches, enabling hardware fault injection. Such attacks could compromise the integrity and confidentiality of data processed by affected devices, potentially leading to unauthorized access or data breaches. This may impact compliance with standards like GDPR and HIPAA, which require robust security measures to protect sensitive data.

Mitigation Strategies

Implement hardware-level protections against voltage and clock glitches such as voltage monitoring and clock signal validation. Ensure secure boot and firmware integrity checks are enabled.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18349. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart