PT-2022-27417 · Nxp · Nxp I.Mx Rt 1015+10
Published
2022-11-18
·
Updated
2022-11-28
·
CVE-2022-45163
CVSS v3.1
5.3
Medium
| Vector | AC:L/AV:P/A:N/C:H/I:N/PR:N/S:C/UI:N |
Name of the Vulnerable Software and Affected Versions
NXP i.MX RT 1010
NXP i.MX RT 1015
NXP i.MX RT 1020
NXP i.MX RT 1050
NXP i.MX RT 1060
NXP i.MX 6 Family
NXP i.MX 7Dual/Solo
NXP i.MX 7ULP
NXP i.MX 8M Quad
NXP i.MX 8M Mini
NXP Vybrid
Description
An information-disclosure issue exists on select NXP devices when configured in Serial Download Protocol (SDP) mode. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks.
Recommendations
For all affected NXP devices, completely disable the SDP mode by programming a one-time programmable eFUSE to mitigate the issue.
Customers can contact NXP for additional information.
Exploit
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nxp Vybrid
Nxp I.Mx 6 Family
Nxp I.Mx 7Dual/Solo
Nxp I.Mx 7Ulp
Nxp I.Mx 8M Mini
Nxp I.Mx 8M Quad
Nxp I.Mx Rt 1010
Nxp I.Mx Rt 1015
Nxp I.Mx Rt 1020
Nxp I.Mx Rt 1050
Nxp I.Mx Rt 1060