Buffer Overflow Vulnerability in NXP LPC55 Microcontrollers
CVE-2022-22819

7.8HIGH

Key Information:

Vendor

Nxp

Vendor
CVE Published:
23 March 2022

What is CVE-2022-22819?

A buffer overflow in the parsing of SB2 updates in certain NXP LPC55 microcontrollers can lead to non-persistent code execution. This vulnerability arises when an attacker crafts an unsigned update that is parsed prior to verification of its signature, thereby circumventing security measures and potentially leading to unauthorized code execution. This issue significantly impacts the security integrity of devices utilizing affected microcontrollers.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.