NXP Semiconductors' vulnerability footprint spans embedded microcontroller and processor families, particularly its MCUXpresso development ecosystem and i.MX application processor lines that power automotive, industrial, and IoT devices across broad deployment bases. The vendor's disclosures cluster around memory-safety and authorization weaknesses—including classic buffer overflows, integer overflows, out-of-bounds reads, and improper access controls—that are characteristic of firmware and kernel-level code in resource-constrained embedded environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the safety-critical and networked nature of devices that embed these processors. Defenders should prioritize inventory and patching of internet-exposed or field-deployable systems running affected processor variants and firmware versions, particularly where update cycles are lengthy or unavailable; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nxp over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27421CRITICAL NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified | May 3, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-22680CRITICAL NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. This unverified memory assignment can lead to arbitrary memor | May 3, 2022 | 9.8 | 30 | NO | NO |
CVE-2019-14237CRITICAL On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by observing CPU r | Sep 12, 2019 | 9.8 | 30 | NO | NO |
CVE-2022-22819HIGH NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates b | Mar 23, 2022 | 7.8 | 26 | NO | NO |
CVE-2019-17519HIGH The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to ca | Feb 12, 2020 | 8.8 | 26 | NO | NO |
CVE-2021-44149HIGH An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security access configuration for wakeup-rel | Dec 7, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-38260HIGH NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostParseDeviceConfigurationDescriptor(). | Oct 25, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-38258HIGH NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback(). | Oct 25, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-36133HIGH The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbit | Dec 7, 2021 | 7.1 | 23 | NO | NO |
CVE-2023-39902HIGH A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family processors. Under certain conditions, a crafte | Oct 17, 2023 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nxp.
Media articles that mention a CVE ID that affects a product developed by Nxp — matched by CVE ID, not by vendor name.