CVE-2022-22819: Buffer Overflow
NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates before the signature is verified. This can allow an attacker to achieve non-persistent code execution via a crafted unsigned update.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this NXP vulnerability?
The vulnerability ID for this NXP vulnerability is CVE-2022-22819.
What is the severity of CVE-2022-22819?
The severity of CVE-2022-22819 is high.
Which microcontrollers are affected by CVE-2022-22819?
The NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers are affected by CVE-2022-22819.
How does the vulnerability in the NXP microcontrollers occur?
The vulnerability in the NXP microcontrollers occurs due to a buffer overflow in parsing SB2 updates before the signature is verified.
Can an attacker achieve code execution with CVE-2022-22819?
Yes, an attacker can achieve non-persistent code execution through a crafted unsigned firmware update.