CVE-2017-18347

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
12/09/2018
Last modified:
04/05/2021

Description

Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wire Debug (SWD) commands because there is a race condition between full initialization of the SWD interface and the setup of flash protection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:st:stm32f071rb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32f071rb:-:*:*:*:*:*:*:*
cpe:2.3:o:st:stm32f071v8_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32f071v8:-:*:*:*:*:*:*:*
cpe:2.3:o:st:stm32f071vb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32f071vb:-:*:*:*:*:*:*:*
cpe:2.3:o:st:stm32f072c8_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32f072c8:-:*:*:*:*:*:*:*
cpe:2.3:o:st:stm32f072cb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32f072cb:-:*:*:*:*:*:*:*
cpe:2.3:o:st:stm32f072r8_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32f072r8:-:*:*:*:*:*:*:*
cpe:2.3:o:st:stm32f072rb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32f072rb:-:*:*:*:*:*:*:*
cpe:2.3:o:st:stm32f072v8_firmware:-:*:*:*:*:*:*:*