Undocumented ROM Patch Vulnerability in NXP Microcontrollers
CVE-2021-31532

6.8MEDIUM

Key Information:

Vendor

Nxp

Vendor
CVE Published:
6 May 2021

What is CVE-2021-31532?

The NXP LPC55S6x series and related microcontrollers exhibit a vulnerability involving an undocumented ROM patch peripheral. This security flaw permits unsigned and non-persistent modifications to the internal ROM, potentially compromising the integrity of the device's firmware. The presence of this undocumented feature underscores significant risks regarding unauthorized alterations and device stability, highlighting the need for robust security measures in the usage of these microcontrollers.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.