Any application that
uses external QSPI flash for encrypted XIP on nRF5340 and relies on that
encryption for confidentiality and/or integrity of the externally stored
code. No specific nRF Connect SDK version is the root cause; the weakness
is in the on-the-fly decryption scheme.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nordic Semiconductor Asa
Nordic Semiconductor Asa nrf5340 |
|
| Vendors & Products |
Nordic Semiconductor Asa
Nordic Semiconductor Asa nrf5340 |
Tue, 08 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored code. No specific nRF Connect SDK version is the root cause; the weakness is in the on-the-fly decryption scheme. | |
| Title | QSPI flash encryption side-channel leakage | |
| Weaknesses | CWE-1342 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: YesWeHack
Published: 2026-09-07T08:07:31.633Z
Updated: 2026-09-10T11:17:10.632Z
Reserved: 2026-08-04T09:40:15.178Z
Link: CVE-2026-18796
Updated: 2026-09-08T15:01:23.790Z
Status : Awaiting Analysis
Published: 2026-09-07T09:17:15.570
Modified: 2026-09-09T15:50:19.447
Link: CVE-2026-18796
No data.