CVE-2024-38532: Usbarmory Mxs-Dcp

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

The NXP Data Co-Processor (DCP) is a built-in hardware module for specific NXP SoCs¹ that implements a dedicated AES cryptographic engine for encryption/decryption operations. The dcp_tool reference implementation included in the repository selected the test key, regardless of its `-t` argument. This issue has been patched in commit 26a7.

Affected products

Published 2024-06-28. Last modified 2026-06-17.