CVE-2024-38532

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-38532
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-38532.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-38532
Related
  • GHSA-g85c-rh49-p8cq
Published
2024-06-28T22:15:03Z
Modified
2025-01-14T19:46:52Z
Summary
[none]
Details

The NXP Data Co-Processor (DCP) is a built-in hardware module for specific NXP SoCs¹ that implements a dedicated AES cryptographic engine for encryption/decryption operations. The dcp_tool reference implementation included in the repository selected the test key, regardless of its -t argument. This issue has been patched in commit 26a7.

References

Affected packages

Git / github.com/usbarmory/mxs-dcp

Affected ranges

Type
GIT
Repo
https://github.com/usbarmory/mxs-dcp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed