ZeroHour

CVE-2017-18347

PoC ×2
CVSS 3.1
4.6 medium
EPSS
<1%p34
Published
()
Modified
Description

Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wire Debug (SWD) commands because there is a race condition between full initialization of the SWD interface and the setup of flash protection.

Vendors
st
Products
stm32f071rb firmware, stm32f071v8 firmware, stm32f071vb firmware, stm32f072c8 firmware, stm32f072cb firmware, stm32f072r8 firmware, stm32f072rb firmware, stm32f072v8 firmware, stm32f072vb firmware, stm32f078cb firmware, stm32f078rb firmware, stm32f078vb firmware
Weakness
CWE-362
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.