任何在 nRF5340 上使用外部 QSPI 闪存进行加密 XIP(就地执行)并依赖该加密来保障外部存储代码的机密性和/或完整性的应用程序。问题的根本原因并非某个特定版本的 nRF Connect SDK,而在于其“即时解密”机制本身存在缺陷。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Nordic Semiconductor ASA | nRF5340 | All build codes | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14297 | 8.7 HIGH | The Continuous Glucose Monitoring Service's Record Access Control Point (RACP) write handl |
| CVE-2026-14296 | 7.5 HIGH | nRF54H20: MCUBoot can be tricked to executing unauthenticated code |
No comments yet