CVE-2019-14239: Medium severity nxp kinetis kv1x firmware vulnerability
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by leveraging a load instruction inside the execute-only region to expose the protected code into a CPU register.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14239?
CVE-2019-14239 is a vulnerability on NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices that allows for the defeat of Flash Access Controls (FAC) by exposing protected code into a CPU register.
What is Flash Access Controls (FAC)?
Flash Access Controls (FAC) is a software IP protection method for execute-only access on NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices.
How can CVE-2019-14239 be exploited?
CVE-2019-14239 can be exploited by leveraging a load instruction inside the execute-only region to expose the protected code into a CPU register.
What is the severity of CVE-2019-14239?
CVE-2019-14239 has a severity rating of 6.6 (medium).
Are there any references for more information on CVE-2019-14239?
Yes, you can find more information on CVE-2019-14239 at the following references: [link1], [link2].