CVE-2022-45163: Medium severity NXP I.mx 6 Firmware vulnerability
An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks. (The recommended mitigation is to completely disable the SDP mode by programming a one-time programmable eFUSE. Customers can contact NXP for additional information.)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Completely disable Serial Download Protocol (SDP) mode by programming a one-time programmable eFUSE (for cold and warm boot attacks that could leak memory contents via the SDP port).
NXP i.MX / Vybrid Serial Download Protocol (SDP) mode SDP mode (enable/disable) = disable - Compensating control
If SDP cannot be disabled immediately, restrict/limit physical and network access to the respective SDP port to reduce exposure to physically proximate attackers during cold and warm boot.
Event History
Frequently Asked Questions
What is CVE-2022-45163?
CVE-2022-45163 is an information-disclosure vulnerability that exists on select NXP devices when configured in Serial Download Protocol (SDP) mode.
Which NXP devices are affected by CVE-2022-45163?
The following NXP devices are affected by CVE-2022-45163: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid.
What is the severity of CVE-2022-45163?
The severity of CVE-2022-45163 is medium, with a severity value of 4.6.
How can I fix CVE-2022-45163?
To fix CVE-2022-45163, apply the necessary patches or updates provided by NXP for your specific device.
Where can I find more information about CVE-2022-45163?
You can find more information about CVE-2022-45163 on the NXP website and the NCC Group technical advisory.