MEDIUM · 6.3

CVE-2017-7936

A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus,...

Vulnerability Description

A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, i.MX 6QuadPlus, Vybrid VF3xx, Vybrid VF5xx, and Vybrid VF6xx. When the device is configured in security enabled configuration, SDP could be used to download a small section of code to an unprotected region of memory.

CVSS Score

6.3

MEDIUM

CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
NxpVybrid Mvf30Nn151Cku26 Firmware-
NxpVybrid Mvf30Nn151Cku26-
NxpVybrid Mvf30Ns151Cku26 Firmware-
NxpVybrid Mvf30Ns151Cku26-
NxpVybrid Mvf50Nn151Cmk40 Firmware-
NxpVybrid Mvf50Nn151Cmk40-
NxpVybrid Mvf50Nn151Cmk50 Firmware-
NxpVybrid Mvf50Nn151Cmk50-
NxpVybrid Mvf50Ns151Cmk40 Firmware-
NxpVybrid Mvf50Ns151Cmk40-
NxpVybrid Mvf50Ns151Cmk50 Firmware-
NxpVybrid Mvf50Ns151Cmk50-
NxpVybrid Mvf51Nn151Cmk50 Firmware-
NxpVybrid Mvf51Nn151Cmk50-
NxpVybrid Mvf51Ns151Cmk50 Firmware-
NxpVybrid Mvf51Ns151Cmk50-
NxpVybrid Mvf60Nn151Cmk40 Firmware-
NxpVybrid Mvf60Nn151Cmk40-
NxpVybrid Mvf60Ns151Cmk40 Firmware-
NxpVybrid Mvf60Ns151Cmk40-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-7936?

CVE-2017-7936 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus,...

How severe is CVE-2017-7936?

CVE-2017-7936 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-7936?

Check the references section above for vendor advisories and patch information. Affected products include: Nxp Vybrid Mvf30Nn151Cku26 Firmware, Nxp Vybrid Mvf30Nn151Cku26, Nxp Vybrid Mvf30Ns151Cku26 Firmware, Nxp Vybrid Mvf30Ns151Cku26, Nxp Vybrid Mvf50Nn151Cmk40 Firmware.