CVE-2022-45163
Summary
| CVE | CVE-2022-45163 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-18 23:15:00 UTC |
| Updated | 2022-11-28 15:21:00 UTC |
| Description | An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks. (The recommended mitigation is to completely disable the SDP mode by programming a one-time programmable eFUSE. Customers can contact NXP for additional information.) |
Risk And Classification
Problem Types: CWE-203
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Nxp | I.mx 6 | - | All | All | All |
| Hardware | Nxp | I.mx 6dual | - | All | All | All |
| Hardware | Nxp | I.mx 6duallite | - | All | All | All |
| Operating System | Nxp | I.mx 6duallite Firmware | - | All | All | All |
| Hardware | Nxp | I.mx 6dualplus | - | All | All | All |
| Operating System | Nxp | I.mx 6dualplus Firmware | - | All | All | All |
| Operating System | Nxp | I.mx 6dual Firmware | - | All | All | All |
| Hardware | Nxp | I.mx 6quad | - | All | All | All |
| Hardware | Nxp | I.mx 6quadplus | - | All | All | All |
| Operating System | Nxp | I.mx 6quadplus Firmware | - | All | All | All |
| Operating System | Nxp | I.mx 6quad Firmware | - | All | All | All |
| Hardware | Nxp | I.mx 6solo | - | All | All | All |
| Hardware | Nxp | I.mx 6sololite | - | All | All | All |
| Operating System | Nxp | I.mx 6sololite Firmware | - | All | All | All |
| Hardware | Nxp | I.mx 6solox | - | All | All | All |
| Operating System | Nxp | I.mx 6solox Firmware | - | All | All | All |
| Operating System | Nxp | I.mx 6solo Firmware | - | All | All | All |
| Hardware | Nxp | I.mx 6ull | - | All | All | All |
| Operating System | Nxp | I.mx 6ull Firmware | - | All | All | All |
| Hardware | Nxp | I.mx 6ultralite | - | All | All | All |
| Operating System | Nxp | I.mx 6ultralite Firmware | - | All | All | All |
| Hardware | Nxp | I.mx 6ulz | - | All | All | All |
| Operating System | Nxp | I.mx 6ulz Firmware | - | All | All | All |
| Operating System | Nxp | I.mx 6 Firmware | - | All | All | All |
| Hardware | Nxp | I.mx 7dual | - | All | All | All |
| Operating System | Nxp | I.mx 7dual Firmware | - | All | All | All |
| Hardware | Nxp | I.mx 7solo | - | All | All | All |
| Operating System | Nxp | I.mx 7solo Firmware | - | All | All | All |
| Hardware | Nxp | I.mx 7ulp | - | All | All | All |
| Operating System | Nxp | I.mx 7ulp Firmware | - | All | All | All |
| Hardware | Nxp | I.mx 8m Mini | - | All | All | All |
| Operating System | Nxp | I.mx 8m Mini Firmware | - | All | All | All |
| Hardware | Nxp | I.mx 8m Quad | - | All | All | All |
| Operating System | Nxp | I.mx 8m Quad Firmware | - | All | All | All |
| Hardware | Nxp | I.mx 8m Vybrid | - | All | All | All |
| Operating System | Nxp | I.mx 8m Vybrid Firmware | - | All | All | All |
| Hardware | Nxp | I.mx Rt1010 | - | All | All | All |
| Operating System | Nxp | I.mx Rt1010 Firmware | - | All | All | All |
| Hardware | Nxp | I.mx Rt1015 | - | All | All | All |
| Operating System | Nxp | I.mx Rt1015 Firmware | - | All | All | All |
| Hardware | Nxp | I.mx Rt1020 | - | All | All | All |
| Operating System | Nxp | I.mx Rt1020 Firmware | - | All | All | All |
| Hardware | Nxp | I.mx Rt1050 | - | All | All | All |
| Operating System | Nxp | I.mx Rt1050 Firmware | - | All | All | All |
| Hardware | Nxp | I.mx Rt1060 | - | All | All | All |
| Operating System | Nxp | I.mx Rt1060 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Automotive, IoT & Industrial Solutions | NXP Semiconductors | MISC | nxp.com | |
| Technical Advisory – NCC Group Research | MISC | research.nccgroup.com | |
| Technical Advisory – NXP i.MX SDP_READ_DISABLE Fuse Bypass (CVE-2022-45163) – NCC Group Research | MISC | research.nccgroup.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.