# CVE-2026-43606

## Summary

- **CVE ID:** CVE-2026-43606
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-208
- **Published:** Aug 11, 2026
- **Last Modified:** Aug 12, 2026

## Description

Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially perform timing analysis or electromagnetic emanation attacks, resulting in high confidentiality and integrity impact due to the exposure of private cryptographic keys.

## Affected Products

- AMD — Vitis™  Libraries - Security Module (2026.1)
- AMD — Vitis™ Unified Installer for FPGAs & Adaptive SoCs in Windows (2026.1)

## References

- [CNA](https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-8015.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.12%
- **EPSS Percentile:** 2.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._