MEDIUM · 6.8

CVE-2021-31532

NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x (silicon rev 0A, 1B), LPC55S1x, LPC551x (silicon rev 0A) and...

Vulnerability Description

NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x (silicon rev 0A, 1B), LPC55S1x, LPC551x (silicon rev 0A) and LPC55S0x, LPC550x (silicon rev 0A) include an undocumented ROM patch peripheral that allows unsigned, non-persistent modification of the internal ROM.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
NxpLpc55S69Jbd100 Firmware-
NxpLpc55S69Jbd1000a
NxpLpc55S66Jbd100 Firmware-
NxpLpc55S66Jbd1000a
NxpLpc55S69Jev98 Firmware-
NxpLpc55S69Jev980a
NxpLpcs66Jev98 Firmware-
NxpLpcs66Jev980a
NxpLpc55S69Jbd64 Firmware-
NxpLpc55S69Jbd640a
NxpLpcs66Jbd64 Firmware-
NxpLpcs66Jbd640a
NxpI.Mx Rt500 Firmware-
NxpI.Mx Rt500b1
NxpI.Mx Rt600 Firmware-
NxpI.Mx Rt600a0
NxpLpc55S28 Firmware-
NxpLpc55S280a
NxpLpc55S26 Firmware-
NxpLpc55S260a

References

FAQ

What is CVE-2021-31532?

CVE-2021-31532 is a vulnerability with a CVSS score of 6.8 (MEDIUM). NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x (silicon rev 0A, 1B), LPC55S1x, LPC551x (silicon rev 0A) and...

How severe is CVE-2021-31532?

CVE-2021-31532 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-31532?

Check the references section above for vendor advisories and patch information. Affected products include: Nxp Lpc55S69Jbd100 Firmware, Nxp Lpc55S69Jbd100, Nxp Lpc55S66Jbd100 Firmware, Nxp Lpc55S66Jbd100, Nxp Lpc55S69Jev98 Firmware.