Vulnerability Description
NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nxp | Lpc55S69Jbd100 Firmware | - |
| Nxp | Lpc55S69Jbd100 | 0a |
| Nxp | Lpc55S69Jbd64 Firmware | - |
| Nxp | Lpc55S69Jbd64 | 0a |
| Nxp | Lpc55S69Jev98 Firmware | - |
| Nxp | Lpc55S69Jev98 | 0a |
Related Weaknesses (CWE)
References
- https://github.com/Xen1thLabs-AE/CVE-2021-40154Third Party Advisory
- https://www.darkmatter.ae/xen1thlabs/published-advisories/Broken LinkThird Party Advisory
- https://github.com/Xen1thLabs-AE/CVE-2021-40154Third Party Advisory
- https://www.darkmatter.ae/xen1thlabs/published-advisories/Broken LinkThird Party Advisory
FAQ
What is CVE-2021-40154?
CVE-2021-40154 is a vulnerability with a CVSS score of 6.1 (MEDIUM). NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of USB In-System Programming (ISP) mode. This discloses protecte...
How severe is CVE-2021-40154?
CVE-2021-40154 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40154?
Check the references section above for vendor advisories and patch information. Affected products include: Nxp Lpc55S69Jbd100 Firmware, Nxp Lpc55S69Jbd100, Nxp Lpc55S69Jbd64 Firmware, Nxp Lpc55S69Jbd64, Nxp Lpc55S69Jev98 Firmware.