Vulnerabilities > CVE-2023-39902 - Improper Preservation of Permissions vulnerability in NXP Uboot Secondary Program Loader

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
nxp
CWE-281

Summary

A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family processors. Under certain conditions, a crafted Flattened Image Tree (FIT) format structure can be used to overwrite SPL memory, allowing unauthenticated software to execute on the target, leading to privilege escalation. This affects i.MX 8M, i.MX 8M Mini, i.MX 8M Nano, and i.MX 8M Plus.

Vulnerable Configurations

Part Description Count
OS
Nxp
1
Hardware
Nxp
4

Common Weakness Enumeration (CWE)