CyberRota Analysis
AI-GeneratedApplications utilizing external QSPI flash for encrypted execute-in-place (XIP) on the nRF5340 are vulnerable due to a weakness in the on-the-fly decryption scheme, which compromises the confidentiality and integrity of the stored code. This vulnerability could allow unauthorized access or manipulation of sensitive data. Organizations using affected F5 products should prioritize addressing this issue to mitigate potential security risks.
Original NVD Description
Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored code. No specific nRF Connect SDK version is the root cause; the weakness is in the on-the-fly decryption scheme.