CVE-2020-27212

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
21/05/2021
Last modified:
08/06/2021

Description

STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by injecting a fault during the boot phase.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:st:stm32cubel4_firmware:*:*:*:*:*:*:*:* 1.16.0 (including)
cpe:2.3:h:st:stm32l412c8:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32l412cb:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32l412k8:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32l412kb:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32l412r8:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32l412rb:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32l412t8:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32l412tb:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32l422cb:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32l422kb:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32l422rb:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32l422tb:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32l431cb:-:*:*:*:*:*:*:*
cpe:2.3:h:st:stm32l431cc:-:*:*:*:*:*:*:*