Vulnerability Description
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by leveraging a load instruction inside the execute-only region to expose the protected code into a CPU register.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nxp | Kinetis Kv1X Firmware | - |
| Nxp | Kinetis Kv1X | - |
| Nxp | Kinetis Kv3X Firmware | - |
| Nxp | Kinetis Kv3X | - |
| Nxp | Kinetis K8X Firmware | - |
| Nxp | Kinetis K8X | - |
Related Weaknesses (CWE)
References
- https://www.usenix.org/conference/woot19/presentation/schinkExploitThird Party Advisory
- https://www.usenix.org/system/files/woot19-paper_schink.pdfExploitMitigationThird Party Advisory
- https://www.usenix.org/conference/woot19/presentation/schinkExploitThird Party Advisory
- https://www.usenix.org/system/files/woot19-paper_schink.pdfExploitMitigationThird Party Advisory
FAQ
What is CVE-2019-14239?
CVE-2019-14239 is a vulnerability with a CVSS score of 6.6 (MEDIUM). On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by leveraging a load instruction insid...
How severe is CVE-2019-14239?
CVE-2019-14239 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14239?
Check the references section above for vendor advisories and patch information. Affected products include: Nxp Kinetis Kv1X Firmware, Nxp Kinetis Kv1X, Nxp Kinetis Kv3X Firmware, Nxp Kinetis Kv3X, Nxp Kinetis K8X Firmware.