Execute-Only Access Flaw in NXP Kinetis Devices
CVE-2019-14237
9.8CRITICAL
What is CVE-2019-14237?
The vulnerability affects NXP Kinetis KV1x, KV3x, and K8x microcontroller devices by compromising their Flash Access Controls (FAC). This IP protection method, designed to ensure execute-only access, can be bypassed through careful observation of CPU registers and the impact of code execution. Such a breach may expose sensitive data and could potentially allow unauthorized manipulation of the protected software.
