CVE-2018-18056 describes a vulnerability in Texas Instruments TM4C, MSP432E, and MSP432P microcontrollers where the eXecute-Only-Memory (XOM) protection can be bypassed. Attackers can single-step through XOM-protected flash memory, observing state changes to reverse-engineer protected instructions. This allows an attacker to act as an "instruction oracle" to infer the functionality of protected code. The CVSS score is 4.6 (Medium), indicating a physical attack vector with high confidentiality impact but no integrity or availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:ti:tm4c123_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:ti:tm4c129_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.