Information Disclosure Vulnerability in NXP i.MX RT and Vybrid Devices
CVE-2022-45163

4.6MEDIUM

Key Information:

Vendor

Nxp

Vendor
CVE Published:
18 November 2022

What is CVE-2022-45163?

An information disclosure vulnerability has been identified in select NXP devices operating in Serial Download Protocol (SDP) mode. Devices such as the i.MX RT series, i.MX 6 Family, i.MX 7 Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid are affected. When configured in a security-enabled setup, sensitive memory contents may be exposed to physically nearby attackers through the SDP port, especially during cold and warm boot conditions. To mitigate this risk, it is advised to completely disable the SDP mode by programming a one-time programmable eFUSE. For further assistance, customers are encouraged to contact NXP.

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.