Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
TEST_KEY used in example dcp_tool reference implementation
Vulnerability Description
The NXP Data Co-Processor (DCP) is a built-in hardware module for specific NXP SoCs¹ that implements a dedicated AES cryptographic engine for encryption/decryption operations. The dcp_tool reference implementation included in the repository selected the test key, regardless of its `-t` argument. This issue has been patched in commit 26a7.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
使用硬编码的密码学密钥
Vulnerability Title
NXP Data Co-Processor 安全漏洞
Vulnerability Description
NXP Data Co-Processor(NXP DCP)是USB armory开源的一个 SoC 的内置硬件模块。用于实现加密/解密操作的专用 AES 加密引擎。 NXP Data Co-Processor 存在安全漏洞,该漏洞源于存储库中包含的dcp_tool参考实现选择了测试密钥。
CVSS Information
N/A
Vulnerability Type
N/A