VYPR

Kinetis K8x

by Nxp

CVEs (3)

  • CVE-2019-14237CriSep 12, 2019
    risk 0.64cvss 9.8epss 0.03

    On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by observing CPU registers and the effect of code/instruction execution.

  • CVE-2019-14239MedSep 24, 2019
    risk 0.43cvss 6.6epss 0.00

    On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by leveraging a load instruction inside the execute-only region to expose the protected code into a CPU register.

  • CVE-2021-44479MedDec 1, 2021
    risk 0.40cvss 6.1epss 0.00

    NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory.