Medium severity6.1NVD Advisory· Published Dec 1, 2021· Updated Jun 17, 2026
CVE-2021-40154
CVE-2021-40154
Description
NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory.
Affected products
5- cpe:2.3:o:nxp:lpc55s69jbd100_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:nxp:lpc55s69jbd64_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:nxp:lpc55s69jev98_firmware:-:*:*:*:*:*:*:*
- NXP/LPC55S69 devicesdescription
Patches
Vulnerability mechanics
References
1- www.darkmatter.ae/xen1thlabs/published-advisories/nvdBroken LinkThird Party Advisory
News mentions
0No linked articles in our index yet.