Critical severity9.8NVD Advisory· Published Sep 12, 2019· Updated Jun 17, 2026
CVE-2019-14236
CVE-2019-14236
Description
On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated by observing CPU registers and the effect of code/instruction execution.
Affected products
14- cpe:2.3:o:st:stm32f4_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:st:stm32f7_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:st:stm32h7_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:st:stm32l0_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:st:stm32l1_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:st:stm32l4_firmware:-:*:*:*:*:*:*:*
- STMicroelectronics/STM32L0description
Patches
Vulnerability mechanics
References
1- www.usenix.org/system/files/woot19-paper_schink.pdfnvdExploitMitigationThird Party Advisory
News mentions
0No linked articles in our index yet.