CVE-2019-14237: Critical severity nxp kinetis kv1x firmware vulnerability
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by observing CPU registers and the effect of code/instruction execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14237?
CVE-2019-14237 is a vulnerability found on NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices where Flash Access Controls (FAC) can be defeated by observing CPU registers and the effect of code/instruction execution.
How does the vulnerability in CVE-2019-14237 work?
The vulnerability in CVE-2019-14237 allows an attacker to defeat the Flash Access Controls (FAC) software IP protection method by observing CPU registers and the effect of code/instruction execution.
What is the severity of CVE-2019-14237?
The severity of CVE-2019-14237 is critical with a CVSS score of 9.8.
Is NXP Kinetis KV1x vulnerable?
No, NXP Kinetis KV1x devices are not vulnerable to CVE-2019-14237.
Is NXP Kinetis KV3x vulnerable?
No, NXP Kinetis KV3x devices are not vulnerable to CVE-2019-14237.
Is NXP Kinetis K8x vulnerable?
No, NXP Kinetis K8x devices are not vulnerable to CVE-2019-14237.
How can I fix CVE-2019-14237?
There is no known fix or patch available for CVE-2019-14237 at the moment. It is recommended to follow the recommendations provided by the vendor.
Where can I find more information about CVE-2019-14237?
You can find more information about CVE-2019-14237 in the following reference: [https://www.usenix.org/system/files/woot19-paper_schink.pdf]