ID

VAR-201708-1393


CVE

CVE-2017-7936


TITLE

plural NXP i.MX and Vybrid Product buffer error vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-007268

DESCRIPTION

A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, i.MX 6QuadPlus, Vybrid VF3xx, Vybrid VF5xx, and Vybrid VF6xx. When the device is configured in security enabled configuration, SDP could be used to download a small section of code to an unprotected region of memory. plural NXP i.MX and Vybrid The product contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. NXPi.MX50 and so on are different series of microprocessor products from NXPSemiconductors of the Netherlands. An attacker could exploit the vulnerability to cause a denial of service. Multiple i.MX Products is prone to multiple local security vulnerabilities. An attacker may exploit these issues to bypass certain security restrictions and perform unauthorized actions or execute arbitrary code within the context of the application. Failed exploit attempts will likely cause a denial-of-service condition. The following products are affected: NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual , i.MX 6Quad, i.MX 6DualPlus, i.MX 6QuadPlus, Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx

Trust: 2.79

sources: NVD: CVE-2017-7936 // JVNDB: JVNDB-2017-007268 // CNVD: CNVD-2017-23001 // BID: 99966 // IVD: 235898d3-c5e6-4883-bf99-cc01c40e3f48 // VULHUB: VHN-116139 // VULMON: CVE-2017-7936

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 235898d3-c5e6-4883-bf99-cc01c40e3f48 // CNVD: CNVD-2017-23001

AFFECTED PRODUCTS

vendor:nxpmodel:i.mx 50scope:eqversion: -

Trust: 1.6

vendor:nxpmodel:i.mx 6ultralitescope:eqversion: -

Trust: 1.6

vendor:nxpmodel:i.mx 6quadscope:eqversion: -

Trust: 1.6

vendor:nxpmodel:i.mx 6soloscope:eqversion: -

Trust: 1.6

vendor:nxpmodel:i.mx 6dualplusscope:eqversion: -

Trust: 1.6

vendor:nxpmodel:i.mx 6soloxscope:eqversion: -

Trust: 1.6

vendor:nxpmodel:i.mx 6quadplusscope:eqversion: -

Trust: 1.6

vendor:nxpmodel:i.mx 6sololitescope:eqversion: -

Trust: 1.6

vendor:nxpmodel:i.mx 6duallitescope:eqversion: -

Trust: 1.6

vendor:nxpmodel:i.mx 6dualscope:eqversion: -

Trust: 1.6

vendor:nxpmodel:vybrid mvf30nn151cku26scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf61ns151cmk50scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf50ns151cmk50scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf50nn151cmk40scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf60ns151cmk40scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:i.mx 6ullscope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf60nn151cmk40scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf62nn151cmk40scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf60ns151cmk50scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf50nn151cmk50scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf30ns151cku26scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf60nn151cmk50scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf51ns151cmk50scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf50ns151cmk40scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf51nn151cmk50scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:i.mx 53scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf61nn151cmk50scope:eqversion: -

Trust: 1.0

vendor:nxp semiconductorsmodel:i.mx 50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 53scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6dualscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6duallitescope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6dualplusscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6quadscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6quadplusscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6soloscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6sololitescope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6soloxscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6ullscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6ultralitescope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf30nn151cku26scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf30ns151cku26scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf50nn151cmk40scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf50nn151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf50ns151cmk40scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf50ns151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf51nn151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf51ns151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf60nn151cmk40scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf60nn151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf60ns151cmk40scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf60ns151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf61nn151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf61ns151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf62nn151cmk40scope: - version: -

Trust: 0.8

vendor:nxpmodel:semiconductors i.mxscope:eqversion:50

Trust: 0.6

vendor:nxpmodel:semiconductors i.mxscope:eqversion:53

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6ullscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6ultralitescope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6sololitescope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6soloscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6duallitescope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6quadscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6soloxscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6dualscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6dualplusscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6quadplusscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors vybrid vf3xxscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors vybrid vf5xxscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors vybrid vf6xxscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors vybrid vf5xxscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors vybrid vf3xxscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors mifare ultralightscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors mifare reader componentsscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors mifare desfire ev1scope: - version: -

Trust: 0.3

vendor:nxpmodel:semiconductors mifare classicscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 7soloscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 7dualscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6ultralitescope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6ullscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6soloxscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6sololitescope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6soloscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6quadplusscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6quadscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6dualplusscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6duallitescope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6dualscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imxscope:eqversion:530

Trust: 0.3

vendor:nxpmodel:semiconductors imxscope:eqversion:500

Trust: 0.3

vendor:nxpmodel:semiconductors imxscope:eqversion:280

Trust: 0.3

vendor:vybrid mvf30nn151cku26model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf60ns151cmk40model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf60nn151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf60ns151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf61nn151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf61ns151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf62nn151cmk40model: - scope:eqversion: -

Trust: 0.2

vendor:i mx 50model: - scope:eqversion: -

Trust: 0.2

vendor:i mx 53model: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6ullmodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6ultralitemodel: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf30ns151cku26model: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6sololitemodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6solomodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6duallitemodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6soloxmodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6dualmodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6quadmodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6quadplusmodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6dualplusmodel: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf50nn151cmk40model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf50nn151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf50ns151cmk40model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf50ns151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf51nn151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf51ns151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf60nn151cmk40model: - scope:eqversion: -

Trust: 0.2

sources: IVD: 235898d3-c5e6-4883-bf99-cc01c40e3f48 // CNVD: CNVD-2017-23001 // BID: 99966 // JVNDB: JVNDB-2017-007268 // CNNVD: CNNVD-201704-924 // NVD: CVE-2017-7936

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-7936
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-7936
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2017-23001
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201704-924
value: MEDIUM

Trust: 0.6

IVD: 235898d3-c5e6-4883-bf99-cc01c40e3f48
value: MEDIUM

Trust: 0.2

VULHUB: VHN-116139
value: MEDIUM

Trust: 0.1

VULMON: CVE-2017-7936
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-7936
severity: MEDIUM
baseScore: 4.4
vectorString: AV:L/AC:M/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2017-23001
severity: MEDIUM
baseScore: 5.2
vectorString: AV:L/AC:H/AU:N/C:P/I:C/A:P
accessVector: LOCAL
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: COMPLETE
availabilityImpact: PARTIAL
exploitabilityScore: 1.9
impactScore: 8.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 235898d3-c5e6-4883-bf99-cc01c40e3f48
severity: MEDIUM
baseScore: 5.2
vectorString: AV:L/AC:H/AU:N/C:P/I:C/A:P
accessVector: LOCAL
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: COMPLETE
availabilityImpact: PARTIAL
exploitabilityScore: 1.9
impactScore: 8.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-116139
severity: MEDIUM
baseScore: 4.4
vectorString: AV:L/AC:M/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-7936
baseSeverity: MEDIUM
baseScore: 6.3
vectorString: CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: PHYSICAL
attackComplexity: HIGH
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.4
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: IVD: 235898d3-c5e6-4883-bf99-cc01c40e3f48 // CNVD: CNVD-2017-23001 // VULHUB: VHN-116139 // VULMON: CVE-2017-7936 // JVNDB: JVNDB-2017-007268 // CNNVD: CNNVD-201704-924 // NVD: CVE-2017-7936

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

problemtype:CWE-121

Trust: 1.0

sources: VULHUB: VHN-116139 // JVNDB: JVNDB-2017-007268 // NVD: CVE-2017-7936

THREAT TYPE

local

Trust: 0.9

sources: BID: 99966 // CNNVD: CNNVD-201704-924

TYPE

Buffer error

Trust: 0.8

sources: IVD: 235898d3-c5e6-4883-bf99-cc01c40e3f48 // CNNVD: CNNVD-201704-924

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-007268

PATCH

title:i.MX & Vybrid Security Vulnerability Errata - ERR010872, ERR010873url:https://community.nxp.com/docs/DOC-334996

Trust: 0.8

title:Patches for multiple NXPi.MX product stack buffer overflow vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/100889

Trust: 0.6

title:Multiple NXP i.MX Product Buffer Error Vulnerability Fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=99740

Trust: 0.6

title:usb-device-securityurl:https://github.com/parallelbeings/usb-device-security

Trust: 0.1

title:advisoriesurl:https://github.com/inversepath/advisories

Trust: 0.1

title:advisoriesurl:https://github.com/f-secure-foundry/advisories

Trust: 0.1

sources: CNVD: CNVD-2017-23001 // VULMON: CVE-2017-7936 // JVNDB: JVNDB-2017-007268 // CNNVD: CNNVD-201704-924

EXTERNAL IDS

db:NVDid:CVE-2017-7936

Trust: 3.7

db:ICS CERTid:ICSA-17-152-02

Trust: 3.5

db:BIDid:99966

Trust: 2.7

db:CNNVDid:CNNVD-201704-924

Trust: 0.9

db:CNVDid:CNVD-2017-23001

Trust: 0.8

db:JVNDBid:JVNDB-2017-007268

Trust: 0.8

db:IVDid:235898D3-C5E6-4883-BF99-CC01C40E3F48

Trust: 0.2

db:VULHUBid:VHN-116139

Trust: 0.1

db:VULMONid:CVE-2017-7936

Trust: 0.1

sources: IVD: 235898d3-c5e6-4883-bf99-cc01c40e3f48 // CNVD: CNVD-2017-23001 // VULHUB: VHN-116139 // VULMON: CVE-2017-7936 // BID: 99966 // JVNDB: JVNDB-2017-007268 // CNNVD: CNNVD-201704-924 // NVD: CVE-2017-7936

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-17-152-02

Trust: 3.5

url:http://www.securityfocus.com/bid/99966

Trust: 2.5

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-7936

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-7936

Trust: 0.8

url:http://www.nxp.com/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/119.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://github.com/parallelbeings/usb-device-security

Trust: 0.1

sources: CNVD: CNVD-2017-23001 // VULHUB: VHN-116139 // VULMON: CVE-2017-7936 // BID: 99966 // JVNDB: JVNDB-2017-007268 // CNNVD: CNNVD-201704-924 // NVD: CVE-2017-7936

CREDITS

Quarkslab.

Trust: 0.3

sources: BID: 99966

SOURCES

db:IVDid:235898d3-c5e6-4883-bf99-cc01c40e3f48
db:CNVDid:CNVD-2017-23001
db:VULHUBid:VHN-116139
db:VULMONid:CVE-2017-7936
db:BIDid:99966
db:JVNDBid:JVNDB-2017-007268
db:CNNVDid:CNNVD-201704-924
db:NVDid:CVE-2017-7936

LAST UPDATE DATE

2025-04-20T23:29:34.844000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-23001date:2017-08-26T00:00:00
db:VULHUBid:VHN-116139date:2019-10-09T00:00:00
db:VULMONid:CVE-2017-7936date:2019-10-09T00:00:00
db:BIDid:99966date:2017-07-26T00:00:00
db:JVNDBid:JVNDB-2017-007268date:2017-09-14T00:00:00
db:CNNVDid:CNNVD-201704-924date:2019-10-17T00:00:00
db:NVDid:CVE-2017-7936date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:IVDid:235898d3-c5e6-4883-bf99-cc01c40e3f48date:2017-08-26T00:00:00
db:CNVDid:CNVD-2017-23001date:2017-08-26T00:00:00
db:VULHUBid:VHN-116139date:2017-08-07T00:00:00
db:VULMONid:CVE-2017-7936date:2017-08-07T00:00:00
db:BIDid:99966date:2017-07-26T00:00:00
db:JVNDBid:JVNDB-2017-007268date:2017-09-14T00:00:00
db:CNNVDid:CNNVD-201704-924date:2017-04-20T00:00:00
db:NVDid:CVE-2017-7936date:2017-08-07T08:29:00.353