uses external QSPI flash for encrypted XIP on nRF5340 and relies on that
encryption for confidentiality and/or integrity of the externally stored
code. No specific nRF Connect SDK version is the root cause; the weakness
is in the on-the-fly decryption scheme.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 08 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nordic Semiconductor Asa
Nordic Semiconductor Asa nrf5340 |
|
| Vendors & Products |
Nordic Semiconductor Asa
Nordic Semiconductor Asa nrf5340 |
Tue, 08 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored code. No specific nRF Connect SDK version is the root cause; the weakness is in the on-the-fly decryption scheme. | |
| Title | QSPI flash encryption side-channel leakage | |
| Weaknesses | CWE-1342 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: YesWeHack
Published:
Updated: 2026-09-08T15:01:26.689Z
Reserved: 2026-08-04T09:40:15.178Z
Link: CVE-2026-18796
Updated: 2026-09-08T15:01:23.790Z
Status : Received
Published: 2026-09-07T09:17:15.570
Modified: 2026-09-08T15:18:42.427
Link: CVE-2026-18796
No data.
OpenCVE Enrichment
Updated: 2026-09-08T20:38:08Z