Vulnerability Description
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by observing CPU registers and the effect of code/instruction execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nxp | Kinetis Kv1X Firmware | - |
| Nxp | Kinetis Kv1X | - |
| Nxp | Kinetis Kv3X Firmware | - |
| Nxp | Kinetis Kv3X | - |
| Nxp | Kinetis K8X Firmware | - |
| Nxp | Kinetis K8X | - |
Related Weaknesses (CWE)
References
- https://www.usenix.org/system/files/woot19-paper_schink.pdfExploitMitigationThird Party Advisory
- https://www.usenix.org/system/files/woot19-paper_schink.pdfExploitMitigationThird Party Advisory
FAQ
What is CVE-2019-14237?
CVE-2019-14237 is a vulnerability with a CVSS score of 9.8 (CRITICAL). On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by observing CPU registers and the eff...
How severe is CVE-2019-14237?
CVE-2019-14237 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-14237?
Check the references section above for vendor advisories and patch information. Affected products include: Nxp Kinetis Kv1X Firmware, Nxp Kinetis Kv1X, Nxp Kinetis Kv3X Firmware, Nxp Kinetis Kv3X, Nxp Kinetis K8X Firmware.