CVE-2022-45163
Last modified
CVE-2022-45163 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks. (The recommended mitigation is to completely disable the SDP mode by programming a one-time programmable eFUSE. Customers can contact NXP for additional information.)
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nxp | I.Mx 6 Firmware | All versions |
| Nxp | I.Mx 6dual Firmware | All versions |
| Nxp | I.Mx 6duallite Firmware | All versions |
| Nxp | I.Mx 6dualplus Firmware | All versions |
| Nxp | I.Mx 6quad Firmware | All versions |
| Nxp | I.Mx 6quadplus Firmware | All versions |
| Nxp | I.Mx 6solo Firmware | All versions |
| Nxp | I.Mx 6sololite Firmware | All versions |
| Nxp | I.Mx 6solox Firmware | All versions |
| Nxp | I.Mx 6ull Firmware | All versions |
| Nxp | I.Mx 6ultralite Firmware | All versions |
| Nxp | I.Mx 6ulz Firmware | All versions |
| Nxp | I.Mx 7dual Firmware | All versions |
| Nxp | I.Mx 7solo Firmware | All versions |
| Nxp | I.Mx 7ulp Firmware | All versions |
| Nxp | I.Mx 8m Mini Firmware | All versions |
| Nxp | I.Mx 8m Quad Firmware | All versions |
| Nxp | I.Mx 8m Vybrid Firmware | All versions |
| Nxp | I.Mx Rt1010 Firmware | All versions |
| Nxp | I.Mx Rt1015 Firmware | All versions |
| Nxp | I.Mx Rt1020 Firmware | All versions |
| Nxp | I.Mx Rt1050 Firmware | All versions |
| Nxp | I.Mx Rt1060 Firmware | All versions |
References
- https://nxp.comProduct
- https://research.nccgroup.com/2022/11/17/cve-2022-45163/Exploit, Technical Description, Third Party Advisory
- https://research.nccgroup.com/category/technical-advisory/Exploit, Technical Description, Third Party Advisory
- https://nxp.comProduct
- https://research.nccgroup.com/2022/11/17/cve-2022-45163/Exploit, Technical Description, Third Party Advisory
- https://research.nccgroup.com/category/technical-advisory/Exploit, Technical Description, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-45163?
How severe is CVE-2022-45163?
How do I fix CVE-2022-45163?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-45152A blind Server-Side Request Forgery (SSRF) vulnerability was…9.1
- CVE-2022-45153An Incorrect Default Permissions vulnerability in saphanaboo…7.8
- CVE-2022-45154A Cleartext Storage of Sensitive Information vulnerability i…5.5
- CVE-2022-45155An Improper Handling of Exceptional Conditions vulnerability…5.5
- CVE-2022-45157A vulnerability has been identified in the way that Rancher …9.1
- CVE-2022-4516Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-45164An issue was discovered in Archibus Web Central 2022.03.01.1…4.3
- CVE-2022-45165An issue was discovered in Archibus Web Central 2022.03.01.1…8.8
- CVE-2022-45166An issue was discovered in Archibus Web Central 2022.03.01.1…4.3
- CVE-2022-45167An issue was discovered in Archibus Web Central 2022.03.01.1…4.3
- CVE-2022-45168An issue was discovered in LIVEBOX Collaboration vDesk throu…6.5
- CVE-2022-45169An issue was discovered in LIVEBOX Collaboration vDesk throu…5.4
Are you affected by CVE-2022-45163?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
