Vulnerabilities (CVE)

Filtered by vendor St Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-50096 1 St 1 X-cube-safea1 2024-01-09 N/A 7.5 HIGH
STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect user-written code that was derived from a published sample application.
CVE-2020-8004 1 St 2 Stm32f1, Stm32f1 Firmware 2021-07-21 5.0 MEDIUM 7.5 HIGH
STMicroelectronics STM32F1 devices have Incorrect Access Control.
CVE-2020-27212 1 St 95 Stm32cubel4 Firmware, Stm32l412c8, Stm32l412cb and 92 more 2021-06-08 4.4 MEDIUM 7.0 HIGH
STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by injecting a fault during the boot phase.