PT-2022-27417 · Nxp · Nxp I.Mx Rt 1015+10

Published

2022-11-18

·

Updated

2022-11-28

·

CVE-2022-45163

CVSS v3.1

5.3

Medium

VectorAC:L/AV:P/A:N/C:H/I:N/PR:N/S:C/UI:N
Name of the Vulnerable Software and Affected Versions NXP i.MX RT 1010 NXP i.MX RT 1015 NXP i.MX RT 1020 NXP i.MX RT 1050 NXP i.MX RT 1060 NXP i.MX 6 Family NXP i.MX 7Dual/Solo NXP i.MX 7ULP NXP i.MX 8M Quad NXP i.MX 8M Mini NXP Vybrid
Description An information-disclosure issue exists on select NXP devices when configured in Serial Download Protocol (SDP) mode. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks.
Recommendations For all affected NXP devices, completely disable the SDP mode by programming a one-time programmable eFUSE to mitigate the issue. Customers can contact NXP for additional information.

Exploit

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2022-45163

Affected Products

Nxp Vybrid
Nxp I.Mx 6 Family
Nxp I.Mx 7Dual/Solo
Nxp I.Mx 7Ulp
Nxp I.Mx 8M Mini
Nxp I.Mx 8M Quad
Nxp I.Mx Rt 1010
Nxp I.Mx Rt 1015
Nxp I.Mx Rt 1020
Nxp I.Mx Rt 1050
Nxp I.Mx Rt 1060