NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.darkmatter.ae/xen1thlabs/published-advisories/ | third party advisory broken link |
https://github.com/Xen1thLabs-AE/CVE-2021-40154 | third party advisory |