Which reference AES implementation? My memory is that the one from the spec has terrible timing side channel attacks... e.g. https://www.redhat.com/en/blog/its-all-question-time-aes-tim... seems to corroborate my memory.
I seem to recall this was remotely exploitable, and exploiting timing side channels has only gotten better since 2014.