CVE-2024-38532: TEST_KEY used in example dcp_tool reference implementation
The NXP Data Co-Processor (DCP) is a built-in hardware module for specific NXP SoCs¹ that implements a dedicated AES cryptographic engine for encryption/decryption operations. The dcptool reference implementation included in the repository selected the test key, regardless of its -t argument. This issue has been patched in commit 26a7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38532?
CVE-2024-38532 has been classified as a medium-severity vulnerability due to potential unauthorized encryption and decryption operations.
How do I fix CVE-2024-38532?
To fix CVE-2024-38532, update to the latest version of the NXP DCP Tool that addresses this vulnerability.
What components are affected by CVE-2024-38532?
CVE-2024-38532 affects the NXP DCP Tool, specifically its implementation of the AES cryptographic engine.
Can CVE-2024-38532 lead to data breaches?
Yes, CVE-2024-38532 can potentially lead to unauthorized access to sensitive data through improper handling of cryptographic keys.
Is there a workaround for CVE-2024-38532?
Currently, the recommended approach is to update the software, as no specific workarounds have been provided for CVE-2024-38532.