5.3
CVE-2022-45163
- EPSS 0.11%
- Published 18.11.2022 23:15:29
- Last modified 30.04.2025 15:15:59
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks. (The recommended mitigation is to completely disable the SDP mode by programming a one-time programmable eFUSE. Customers can contact NXP for additional information.)
Data is provided by the National Vulnerability Database (NVD)
Nxp ≫ I.Mx 6 Firmware Version-
Nxp ≫ I.Mx 6dual Firmware Version-
Nxp ≫ I.Mx 6duallite Firmware Version-
Nxp ≫ I.Mx 6dualplus Firmware Version-
Nxp ≫ I.Mx 6quad Firmware Version-
Nxp ≫ I.Mx 6quadplus Firmware Version-
Nxp ≫ I.Mx 6solo Firmware Version-
Nxp ≫ I.Mx 6sololite Firmware Version-
Nxp ≫ I.Mx 6solox Firmware Version-
Nxp ≫ I.Mx 6ull Firmware Version-
Nxp ≫ I.Mx 6ultralite Firmware Version-
Nxp ≫ I.Mx 6ulz Firmware Version-
Nxp ≫ I.Mx 7dual Firmware Version-
Nxp ≫ I.Mx 7solo Firmware Version-
Nxp ≫ I.Mx 7ulp Firmware Version-
Nxp ≫ I.Mx 8m Mini Firmware Version-
Nxp ≫ I.Mx 8m Quad Firmware Version-
Nxp ≫ I.Mx 8m Vybrid Firmware Version-
Nxp ≫ I.Mx Rt1010 Firmware Version-
Nxp ≫ I.Mx Rt1015 Firmware Version-
Nxp ≫ I.Mx Rt1020 Firmware Version-
Nxp ≫ I.Mx Rt1050 Firmware Version-
Nxp ≫ I.Mx Rt1060 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.11% | 0.307 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.6 | 0.9 | 3.6 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
cve@mitre.org | 5.3 | 0.9 | 4 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
|
CWE-203 Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.