CVE-2020-27212
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
21/05/2021
Last modified:
08/06/2021
Description
STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by injecting a fault during the boot phase.
Impact
Base Score 3.x
7.00
Severity 3.x
HIGH
Base Score 2.0
4.40
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:st:stm32cubel4_firmware:*:*:*:*:*:*:*:* | 1.16.0 (including) | |
cpe:2.3:h:st:stm32l412c8:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:st:stm32l412cb:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:st:stm32l412k8:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:st:stm32l412kb:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:st:stm32l412r8:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:st:stm32l412rb:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:st:stm32l412t8:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:st:stm32l412tb:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:st:stm32l422cb:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:st:stm32l422kb:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:st:stm32l422rb:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:st:stm32l422tb:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:st:stm32l431cb:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:st:stm32l431cc:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page