Vulnerabilities
Vulnerable Software
St:  Security Vulnerabilities
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.
CVSS Score
5.9
EPSS Score
0.009
Published
2021-01-20
STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.
CVSS Score
6.8
EPSS Score
0.004
Published
2020-08-31
STMicroelectronics STM32F1 devices have Incorrect Access Control.
CVSS Score
7.5
EPSS Score
0.03
Published
2020-04-06
The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not properly handle consecutive Attribute Protocol (ATT) requests on reception, allowing attackers in radio range to cause an event deadlock or crash via crafted packets.
CVSS Score
6.5
EPSS Score
0.01
Published
2020-02-12
STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.
CVSS Score
5.9
EPSS Score
0.033
Published
2019-11-14
On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with a debug probe via the Instruction Tightly Coupled Memory (ITCM) bus.
CVSS Score
6.6
EPSS Score
0.004
Published
2019-09-24
On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated by observing CPU registers and the effect of code/instruction execution.
CVSS Score
9.8
EPSS Score
0.023
Published
2019-09-12
Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wire Debug (SWD) commands because there is a race condition between full initialization of the SWD interface and the setup of flash protection.
CVSS Score
4.6
EPSS Score
0.004
Published
2018-09-12
Directory traversal vulnerability in ST FTP Service 3.0 allows remote attackers to list arbitrary directories via a CD command with a DoS drive letter argument (e.g. E:).
CVSS Score
6.4
EPSS Score
0.014
Published
2003-07-02


Contact Us

Shodan ® - All rights reserved