CVE-2021-31532
NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x (silicon rev 0A, 1B), LPC55S1x, LPC551x (silicon rev 0A) and LPC55S0x, LPC550x (silicon rev 0A) include an…
Does this matter?
Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.
Description
NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x (silicon rev 0A, 1B), LPC55S1x, LPC551x (silicon rev 0A) and LPC55S0x, LPC550x (silicon rev 0A) include an undocumented ROM patch peripheral that allows unsigned, non-persistent modification of the internal ROM.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Affected
- nxp/lpc55s69jbd100 firmware · nxp/lpc55s66jbd100 firmware · nxp/lpc55s69jev98 firmware · nxp/lpcs66jev98 firmware · nxp/lpc55s69jbd64 firmware · nxp/lpcs66jbd64 firmware · nxp/i.mx rt500 firmware · nxp/i.mx rt600 firmware · nxp/lpc55s28 firmware · nxp/lpc55s26 firmware · nxp/lpc5528 firmware · nxp/lpc5526 firmware · nxp/lpc55s16jbd100 firmware · nxp/lpc55s16jev98 firmware · nxp/lpc55s16jbd64 firmware · nxp/lpc55s14jbd100 firmware · nxp/lpc55s14jbd64 firmware · nxp/lpc5516jbd100 firmware · nxp/lpc5516jev98 firmware · nxp/lpc5516jbd64 firmware · +4 more
- Source
- cve@mitre.org
References
- https://oxide.computer/blog/lpc55/Exploit, Third Party Advisory
- https://www.nxp.comVendor Advisory
- https://oxide.computer/blog/lpc55/Exploit, Third Party Advisory
- https://www.nxp.comVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.