NXP records
20 published records for vendor nxp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')5
- CWE-125 Out-of-bounds Read2
- CWE-190 Integer Overflow or Wraparound2
- CWE-863 Incorrect Authorization2
- CWE-203 Observable Discrepancy1
- CWE-281 Improper Preservation of Permissions1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-14237No exploit | On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only acnxp · kinetis kv1x firmware · CWE-863 | Critical9.8 | — | 2.9% | Sep 12, 2019 |
39Monitor | CVE-2021-22680No exploit | NXP MQX Integer Overflow or Wraparoundnxp · mqx · CWE-190 | Critical9.8 | — | 1.6% | May 3, 2022 |
39Monitor | CVE-2021-27421No exploit | NXP MCUXpresso SDK Integer Overflow or Wraparoundnxp · mcuxpresso software development kit · CWE-190 | Critical9.8 | — | 0.9% | May 3, 2022 |
35Monitor | CVE-2019-17519No exploit | The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length,nxp · mcuxpresso software development kit · CWE-120 | High8.8 | — | 1.2% | Feb 12, 2020 |
31Monitor | CVE-2022-22819No exploit | NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a nxp · lpc55s66jbd64 firmware · CWE-120 | High7.8 | — | 1.4% | Mar 23, 2022 |
31Monitor | CVE-2021-44149No exploit | An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0.trustedfirmware · op-tee | High7.8 | — | 0.3% | Dec 7, 2021 |
31Monitor | CVE-2021-38260No exploit | NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostParseDeviceConfigurationDescriptor().nxp · mcuxpresso software development kit · CWE-120 | High7.8 | — | 0.3% | Oct 25, 2021 |
31Monitor | CVE-2021-38258No exploit | NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback().nxp · mcuxpresso software development kit · CWE-120 | High7.8 | — | 0.3% | Oct 25, 2021 |
31Monitor | CVE-2023-39902No exploit | A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family procesnxp · uboot secondary program loader · CWE-281 | High7.8 | — | 0.2% | Oct 17, 2023 |
28Monitor | CVE-2021-36133No exploit | The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass becaunxp · i.mx 6 · CWE-732 | High7.1 | — | 0.3% | Dec 7, 2021 |
27Monitor | CVE-2021-31532No exploit | NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x nxp · lpc55s69jbd100 firmware | Medium6.8 | — | 0.5% | May 6, 2021 |
26Monitor | CVE-2019-17060No exploit | The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Energy Driver 2.2.1 andnxp · mcuxpresso software development kit · CWE-120 | Medium6.5 | — | 0.8% | Feb 10, 2020 |
26Monitor | CVE-2019-14239No exploit | On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only acnxp · kinetis kv1x firmware · CWE-287 | Medium6.6 | — | 0.4% | Sep 24, 2019 |
25Monitor | CVE-2017-7936No exploit | A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6Dunxp · vybrid mvf30nn151cku26 firmware · CWE-121 | Medium6.3 | — | 0.3% | Aug 7, 2017 |
24Monitor | CVE-2017-7932No exploit | An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vnxp · vybrid mvf30nn151cku26 firmware · CWE-295 | Medium6.0 | — | 0.3% | Aug 7, 2017 |
22Monitor | CVE-2021-40154Proof of concept | NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of Unxp · lpc55s69jbd100 firmware · CWE-125 | Medium5.5 | — | 0.8% | Dec 1, 2021 |
22Monitor | CVE-2021-44479No exploit | NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of USB In-System Progranxp · kinetis k82 firmware · CWE-125 | Medium5.5 | — | 0.3% | Dec 1, 2021 |
18Monitor | CVE-2022-45163No exploit | An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, inxp · i.mx 6 firmware · CWE-203 | Medium4.6 | — | 0.6% | Nov 18, 2022 |
16Monitor | CVE-2021-33881No exploit | On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) over RFID to bypass anxp · mifare ultralight ev1 firmware · CWE-863 | Medium4.2 | — | 0.4% | Jun 6, 2021 |
16Monitor | CVE-2021-3011No exploit | An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication micronxp · 3a081 · CWE-670 | Medium4.2 | — | 0.2% | Jan 7, 2021 |
- CVE-2019-1423740Plan
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only ac
CriticalCVSS 9.8No exploitEPSS 3%nxp · kinetis kv1x firmwareSep 12, 2019
- CVE-2021-2268039Monitor
NXP MQX Integer Overflow or Wraparound
CriticalCVSS 9.8No exploitEPSS 2%nxp · mqxMay 3, 2022
- CVE-2021-2742139Monitor
NXP MCUXpresso SDK Integer Overflow or Wraparound
CriticalCVSS 9.8No exploitEPSS 1%nxp · mcuxpresso software development kitMay 3, 2022
- CVE-2019-1751935Monitor
The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length,
HighCVSS 8.8No exploitEPSS 1%nxp · mcuxpresso software development kitFeb 12, 2020
- CVE-2022-2281931Monitor
NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a
HighCVSS 7.8No exploitEPSS 1%nxp · lpc55s66jbd64 firmwareMar 23, 2022
- CVE-2021-4414931Monitor
An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0.
HighCVSS 7.8No exploitEPSS 0%trustedfirmware · op-teeDec 7, 2021
- CVE-2021-3826031Monitor
NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostParseDeviceConfigurationDescriptor().
HighCVSS 7.8No exploitEPSS 0%nxp · mcuxpresso software development kitOct 25, 2021
- CVE-2021-3825831Monitor
NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback().
HighCVSS 7.8No exploitEPSS 0%nxp · mcuxpresso software development kitOct 25, 2021
- CVE-2023-3990231Monitor
A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family proces
HighCVSS 7.8No exploitEPSS 0%nxp · uboot secondary program loaderOct 17, 2023
- CVE-2021-3613328Monitor
The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass becau
HighCVSS 7.1No exploitEPSS 0%nxp · i.mx 6Dec 7, 2021
- CVE-2021-3153227Monitor
NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x
MediumCVSS 6.8No exploitEPSS 0%nxp · lpc55s69jbd100 firmwareMay 6, 2021
- CVE-2019-1706026Monitor
The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Energy Driver 2.2.1 and
MediumCVSS 6.5No exploitEPSS 1%nxp · mcuxpresso software development kitFeb 10, 2020
- CVE-2019-1423926Monitor
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only ac
MediumCVSS 6.6No exploitEPSS 0%nxp · kinetis kv1x firmwareSep 24, 2019
- CVE-2017-793625Monitor
A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6Du
MediumCVSS 6.3No exploitEPSS 0%nxp · vybrid mvf30nn151cku26 firmwareAug 7, 2017
- CVE-2017-793224Monitor
An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, V
MediumCVSS 6.0No exploitEPSS 0%nxp · vybrid mvf30nn151cku26 firmwareAug 7, 2017
- CVE-2021-4015422Monitor
NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of U
MediumCVSS 5.5Proof of conceptEPSS 1%nxp · lpc55s69jbd100 firmwareDec 1, 2021
- CVE-2021-4447922Monitor
NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of USB In-System Progra
MediumCVSS 5.5No exploitEPSS 0%nxp · kinetis k82 firmwareDec 1, 2021
- CVE-2022-4516318Monitor
An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i
MediumCVSS 4.6No exploitEPSS 1%nxp · i.mx 6 firmwareNov 18, 2022
- CVE-2021-3388116Monitor
On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) over RFID to bypass a
MediumCVSS 4.2No exploitEPSS 0%nxp · mifare ultralight ev1 firmwareJun 6, 2021
- CVE-2021-301116Monitor
An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication micro
MediumCVSS 4.2No exploitEPSS 0%nxp · 3a081Jan 7, 2021