Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-14236


On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated by observing CPU registers and the effect of code/instruction execution.


Published

2019-09-12T18:15:11.927

Last Modified

2024-11-21T04:26:15.847

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System st stm32l0_firmware - Yes
Hardware st stm32l0 - No
Operating System st stm32l1_firmware - Yes
Hardware st stm32l1 - No
Operating System st stm32f4_firmware - Yes
Hardware st stm32f4 - No
Operating System st stm32l4_firmware - Yes
Hardware st stm32l4 - No
Operating System st stm32f7_firmware - Yes
Hardware st stm32f7 - No
Operating System st stm32h7_firmware - Yes
Hardware st stm32h7 - No

References