CVE-2021-31532
Last modified
CVE-2021-31532 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x (silicon rev 0A, 1B), LPC55S1x, LPC551x (silicon rev 0A) and LPC55S0x, LPC550x (silicon rev 0A) include an undocumented ROM patch peripheral that allows unsigned, non-persistent modification of the internal ROM.. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x (silicon rev 0A, 1B), LPC55S1x, LPC551x (silicon rev 0A) and LPC55S0x, LPC550x (silicon rev 0A) include an undocumented ROM patch peripheral that allows unsigned, non-persistent modification of the internal ROM.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nxp | Lpc55s69jbd100 Firmware | All versions |
| Nxp | Lpc55s66jbd100 Firmware | All versions |
| Nxp | Lpc55s69jev98 Firmware | All versions |
| Nxp | Lpcs66jev98 Firmware | All versions |
| Nxp | Lpc55s69jbd64 Firmware | All versions |
| Nxp | Lpcs66jbd64 Firmware | All versions |
| Nxp | I.Mx Rt500 Firmware | All versions |
| Nxp | I.Mx Rt600 Firmware | All versions |
| Nxp | Lpc55s28 Firmware | All versions |
| Nxp | Lpc55s26 Firmware | All versions |
| Nxp | Lpc5528 Firmware | All versions |
| Nxp | Lpc5526 Firmware | All versions |
| Nxp | Lpc55s16jbd100 Firmware | All versions |
| Nxp | Lpc55s16jev98 Firmware | All versions |
| Nxp | Lpc55s16jbd64 Firmware | All versions |
| Nxp | Lpc55s14jbd100 Firmware | All versions |
| Nxp | Lpc55s14jbd64 Firmware | All versions |
| Nxp | Lpc5516jbd100 Firmware | All versions |
| Nxp | Lpc5516jev98 Firmware | All versions |
| Nxp | Lpc5516jbd64 Firmware | All versions |
| Nxp | Lpc5514jbd100 Firmware | All versions |
| Nxp | Lpc5514jbd64 Firmware | All versions |
| Nxp | Lpc5512jbd100 Firmware | All versions |
| Nxp | Lpc5512jbd64 Firmware | All versions |
References
- https://oxide.computer/blog/lpc55/Exploit, Third Party Advisory
- https://www.nxp.comVendor Advisory
- https://oxide.computer/blog/lpc55/Exploit, Third Party Advisory
- https://www.nxp.comVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31532?
How severe is CVE-2021-31532?
How do I fix CVE-2021-31532?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-31522Kylin can receive user input and load any class through Clas…9.8
- CVE-2021-31523The Debian xscreensaver 5.42+dfsg1-1 package for XScreenSave…7.8
- CVE-2021-31525net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allow…5.9
- CVE-2021-3153HashiCorp Terraform Enterprise up to v202102-2 failed to enf…6.5
- CVE-2021-31530Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulne…7.5
- CVE-2021-31531Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulne…9.8
- CVE-2021-31535LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7…9.8
- CVE-2021-31537SIS SIS-REWE Go before 7.7 SP17 allows XSS: rewe/prod/web/in…6.1
- CVE-2021-31538LANCOM R&S Unified Firewall (UF) devices running LCOS FX 10.…7.5
- CVE-2021-31539Wowza Streaming Engine before 4.8.8.01 (in a default install…5.5
- CVE-2021-3154An issue was discovered in SolarWinds Serv-U before 15.2.2. …7.5
- CVE-2021-31540Wowza Streaming Engine through 4.8.5 (in a default installat…7.1
Are you affected by CVE-2021-31532?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
