9.8

CVE-2019-14236

Exploit
On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated by observing CPU registers and the effect of code/instruction execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
St ≫ Stm32l0 Firmware Version -
   St ≫ Stm32l0 Version -
St ≫ Stm32l1 Firmware Version -
   St ≫ Stm32l1 Version -
St ≫ Stm32f4 Firmware Version -
   St ≫ Stm32f4 Version -
St ≫ Stm32l4 Firmware Version -
   St ≫ Stm32l4 Version -
St ≫ Stm32f7 Firmware Version -
   St ≫ Stm32f7 Version -
St ≫ Stm32h7 Firmware Version -
   St ≫ Stm32h7 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.26% 0.807
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://www.usenix.org/system/files/woot19-paper_schink.pdf
Third Party Advisory
Exploit
Mitigation