On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by leveraging a load instruction inside the execute-only region to expose the protected code into a CPU register.
2019-09-24T19:15:11.333
2024-11-21T04:26:16.327
Modified
CVSSv3.1: 6.6 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | nxp | kinetis_kv1x_firmware | - | Yes |
Hardware | nxp | kinetis_kv1x | - | No |
Operating System | nxp | kinetis_kv3x_firmware | - | Yes |
Hardware | nxp | kinetis_kv3x | - | No |
Operating System | nxp | kinetis_k8x_firmware | - | Yes |
Hardware | nxp | kinetis_k8x | - | No |