STM32L4
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-14236 | Cri | 0.64 | 9.8 | 0.02 | Sep 12, 2019 | On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated by observing CPU registers and the effect of code/instruction execution. | ||
| CVE-2020-27212 | Hig | 0.46 | 7.0 | 0.00 | May 21, 2021 | STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by injecting a fault during the boot phase. | ||
| CVE-2021-29414 | Med | 0.40 | 6.1 | 0.00 | May 21, 2021 | STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control. |
- risk 0.64cvss 9.8epss 0.02
On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated by observing CPU registers and the effect of code/instruction execution.
- risk 0.46cvss 7.0epss 0.00
STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by injecting a fault during the boot phase.
- risk 0.40cvss 6.1epss 0.00
STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.