CVE-2022-45163 - CVE House
Back to Database
Status published Medium CVE-2022-45163

An information-disclosure vulnerability exists on select NXP devices when configured...

Vulnerability Description

An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks. (The recommended mitigation is to completely disable the SDP mode by programming a one-time programmable eFUSE. Customers can contact NXP for additional information.)

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-45163

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

i.mx 6 firmware, i.mx 6dual firmware, i.mx 6duallite firmware, i.mx 6dualplus firmware, i.mx 6quad firmware, i.mx 6quadplus firmware, i.mx 6solo firmware, i.mx 6sololite firmware, i.mx 6solox firmware, i.mx 6ull firmware, i.mx 6ultralite firmware, i.mx 6ulz firmware, i.mx 7dual firmware, i.mx 7solo firmware, i.mx 7ulp firmware, i.mx 8m mini firmware, i.mx 8m quad firmware, i.mx 8m vybrid firmware, i.mx rt1010 firmware, i.mx rt1015 firmware, i.mx rt1020 firmware, i.mx rt1050 firmware, i.mx rt1060 firmware
Vulnerable Versions:
Unknown

Timeline

Official Publish: November 18th, 2022
Last Modified: April 30th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AC:L/AV:P/A:N/C:H/I:N/PR:N/S:C/UI:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.