Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nxp

First CVE: Aug 7, 2017Active for: 9 yearsTotal CVEs: 20
18.9
VTI Score
Low

NXP Semiconductors' vulnerability footprint spans embedded microcontroller and processor families, particularly its MCUXpresso development ecosystem and i.MX application processor lines that power automotive, industrial, and IoT devices across broad deployment bases. The vendor's disclosures cluster around memory-safety and authorization weaknesses—including classic buffer overflows, integer overflows, out-of-bounds reads, and improper access controls—that are characteristic of firmware and kernel-level code in resource-constrained embedded environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the safety-critical and networked nature of devices that embed these processors. Defenders should prioritize inventory and patching of internet-exposed or field-deployable systems running affected processor variants and firmware versions, particularly where update cycles are lengthy or unavailable; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nxp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 7, 2017
8 years ago
Most Recent CVE
Oct 17, 2023
1,011 days ago

Products(213 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-27421CRITICAL
NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified
May 3, 20229.831NONO
CVE-2021-22680CRITICAL
NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. This unverified memory assignment can lead to arbitrary memor
May 3, 20229.830NONO
CVE-2019-14237CRITICAL
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by observing CPU r
Sep 12, 20199.830NONO
CVE-2022-22819HIGH
NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates b
Mar 23, 20227.826NONO
CVE-2019-17519HIGH
The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to ca
Feb 12, 20208.826NONO
CVE-2021-44149HIGH
An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security access configuration for wakeup-rel
Dec 7, 20217.825NONO
CVE-2021-38260HIGH
NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostParseDeviceConfigurationDescriptor().
Oct 25, 20217.825NONO
CVE-2021-38258HIGH
NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback().
Oct 25, 20217.825NONO
CVE-2021-36133HIGH
The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbit
Dec 7, 20217.123NONO
CVE-2023-39902HIGH
A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family processors. Under certain conditions, a crafte
Oct 17, 20237.822NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
50%
35%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local8 (40.0%)
Network3 (15.0%)
Unknown0 (0.0%)
Physical7 (35.0%)
Adjacent Network2 (10.0%)
Attack Complexity
Low16 (80.0%)
High4 (20.0%)
Unknown0 (0.0%)
User Interaction
None19 (95.0%)
Unknown0 (0.0%)
Required1 (5.0%)
Privileges Required
Low9 (45.0%)
High0 (0.0%)
None11 (55.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nxp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nxp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nxp's Products

View all 2 CNAs →

Top CWEs