NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory.
2021-12-01T15:15:07.603
2024-11-21T06:23:40.750
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | nxp | lpc55s69jbd100_firmware | - | Yes |
Hardware | nxp | lpc55s69jbd100 | 0a | No |
Operating System | nxp | lpc55s69jbd100_firmware | - | Yes |
Hardware | nxp | lpc55s69jbd100 | 1b | No |
Operating System | nxp | lpc55s69jbd64_firmware | - | Yes |
Hardware | nxp | lpc55s69jbd64 | 0a | No |
Operating System | nxp | lpc55s69jbd64_firmware | - | Yes |
Hardware | nxp | lpc55s69jbd64 | 1b | No |
Operating System | nxp | lpc55s69jev98_firmware | - | Yes |
Hardware | nxp | lpc55s69jev98 | 0a | No |
Operating System | nxp | lpc55s69jev98_firmware | - | Yes |
Hardware | nxp | lpc55s69jev98 | 1b | No |