CVE Feed

    Dashboard / CVE / CVE-2022-45163

    CVE-2022-45163

    An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks. (The recommended mitigation is to completely disable the SDP mode by programming a one-time programmable eFUSE. Customers can contact NXP for additional information.)

    Published:Nov 18, 2022
    Last Modified:Apr 30, 2025
    EPS:Nov 18, 2022
    EPSS Score:0.00148
    CVSS Score:5.3

    Affected Products

    Vendor
    Nxp
    Product
    I.mx 6
    Vendor
    Nxp
    Product
    I.mx 6 Firmware
    Vendor
    Nxp
    Product
    I.mx 6dual
    Vendor
    Nxp
    Product
    I.mx 6dual Firmware
    Vendor
    Nxp
    Product
    I.mx 6duallite
    Vendor
    Nxp
    Product
    I.mx 6duallite Firmware
    Vendor
    Nxp
    Product
    I.mx 6dualplus
    Vendor
    Nxp
    Product
    I.mx 6dualplus Firmware
    Vendor
    Nxp
    Product
    I.mx 6quad
    Vendor
    Nxp
    Product
    I.mx 6quad Firmware
    Vendor
    Nxp
    Product
    I.mx 6quadplus
    Vendor
    Nxp
    Product
    I.mx 6quadplus Firmware
    Vendor
    Nxp
    Product
    I.mx 6solo
    Vendor
    Nxp
    Product
    I.mx 6solo Firmware
    Vendor
    Nxp
    Product
    I.mx 6sololite
    Vendor
    Nxp
    Product
    I.mx 6sololite Firmware
    Vendor
    Nxp
    Product
    I.mx 6solox
    Vendor
    Nxp
    Product
    I.mx 6solox Firmware
    Vendor
    Nxp
    Product
    I.mx 6ull
    Vendor
    Nxp
    Product
    I.mx 6ull Firmware
    Vendor
    Nxp
    Product
    I.mx 6ultralite
    Vendor
    Nxp
    Product
    I.mx 6ultralite Firmware
    Vendor
    Nxp
    Product
    I.mx 6ulz
    Vendor
    Nxp
    Product
    I.mx 6ulz Firmware
    Vendor
    Nxp
    Product
    I.mx 7dual
    Vendor
    Nxp
    Product
    I.mx 7dual Firmware
    Vendor
    Nxp
    Product
    I.mx 7solo
    Vendor
    Nxp
    Product
    I.mx 7solo Firmware
    Vendor
    Nxp
    Product
    I.mx 7ulp
    Vendor
    Nxp
    Product
    I.mx 7ulp Firmware
    Vendor
    Nxp
    Product
    I.mx 8m Mini
    Vendor
    Nxp
    Product
    I.mx 8m Mini Firmware
    Vendor
    Nxp
    Product
    I.mx 8m Quad
    Vendor
    Nxp
    Product
    I.mx 8m Quad Firmware
    Vendor
    Nxp
    Product
    I.mx 8m Vybrid
    Vendor
    Nxp
    Product
    I.mx 8m Vybrid Firmware
    Vendor
    Nxp
    Product
    I.mx Rt1010
    Vendor
    Nxp
    Product
    I.mx Rt1010 Firmware
    Vendor
    Nxp
    Product
    I.mx Rt1015
    Vendor
    Nxp
    Product
    I.mx Rt1015 Firmware
    Vendor
    Nxp
    Product
    I.mx Rt1020
    Vendor
    Nxp
    Product
    I.mx Rt1020 Firmware
    Vendor
    Nxp
    Product
    I.mx Rt1050
    Vendor
    Nxp
    Product
    I.mx Rt1050 Firmware
    Vendor
    Nxp
    Product
    I.mx Rt1060
    Vendor
    Nxp
    Product
    I.mx Rt1060 Firmware

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High