CVE-2019-14239: Nxp Kinetis k8x Firmware

Medium severity, CVSS 6.6. EPSS: 0.4% chance of exploitation in the next 30 days.

On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by leveraging a load instruction inside the execute-only region to expose the protected code into a CPU register.

Affected products

  • Nxp Kinetis k8x Firmware: affected versions not specified
  • Nxp Kinetis KV1X Firmware: affected versions not specified
  • Nxp Kinetis KV3X Firmware: affected versions not specified

Published 2019-09-24. Last modified 2026-06-17.