CVE-2021-40154: Medium severity nxp lpc55s69 firmware vulnerability
NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-40154?
CVE-2021-40154 is a vulnerability found in NXP LPC55S69 devices before A3 that allows for a buffer over-read.
How does CVE-2021-40154 work?
CVE-2021-40154 works by exploiting a crafted wlength value in a GET Descriptor Configuration request during the use of USB In-System Programming (ISP) mode, which leads to a buffer over-read and discloses protected flash memory.
What is the severity of CVE-2021-40154?
The severity of CVE-2021-40154 is medium, with a severity value of 5.5.
Which software versions are affected by CVE-2021-40154?
NXP LPC55S69 devices before A3 are affected by CVE-2021-40154.
How can I fix CVE-2021-40154?
To fix CVE-2021-40154, it is recommended to apply the necessary firmware updates provided by NXP for the LPC55S69 devices.