CVE-2019-14239
 
Severity Score
6.6
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by leveraging a load instruction inside the execute-only region to expose the protected code into a CPU register.
En los dispositivos NXP Kinetis KV1x, Kinetis KV3x y Kinetis K8x, Flash Access Controls (FAC) (un método de protección de IP de software para acceso solo de ejecución) pueden ser superados mediante el aprovechamiento de una instrucción de carga dentro de la región de solo ejecución para exponer el código protegido en un registro de la CPU.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-07-22 CVE Reserved
- 2019-09-24 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.usenix.org/conference/woot19/presentation/schink | 2024-08-05 | |
https://www.usenix.org/system/files/woot19-paper_schink.pdf | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nxp Search vendor "Nxp" | Kinetis Kv1x Firmware Search vendor "Nxp" for product "Kinetis Kv1x Firmware" | - | - |
Affected
| in | Nxp Search vendor "Nxp" | Kinetis Kv1x Search vendor "Nxp" for product "Kinetis Kv1x" | - | - |
Safe
|
Nxp Search vendor "Nxp" | Kinetis Kv3x Firmware Search vendor "Nxp" for product "Kinetis Kv3x Firmware" | - | - |
Affected
| in | Nxp Search vendor "Nxp" | Kinetis Kv3x Search vendor "Nxp" for product "Kinetis Kv3x" | - | - |
Safe
|
Nxp Search vendor "Nxp" | Kinetis K8x Firmware Search vendor "Nxp" for product "Kinetis K8x Firmware" | - | - |
Affected
| in | Nxp Search vendor "Nxp" | Kinetis K8x Search vendor "Nxp" for product "Kinetis K8x" | - | - |
Safe
|