CVE-2021-44479

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
01/12/2021
Last modified:
16/12/2021

Description

NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:nxp:kinetis_k82_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nxp:kinetis_k82:-:*:*:*:*:*:*:*