V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2019-14236
CVE
Critical

On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a sof…

CVSS
9.8
Critical
EPSS
0.02
p80
Published
2019-01-01
Updated
2019-01-01
Description

On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated by observing CPU registers and the effect of code/instruction execution.

Tags · CWE
Pre-auth
CWE-863
Affected products
Stm32f4_firmwareStm32f7_firmwareStm32h7_firmwareStm32l0_firmwareStm32l1_firmwareStm32l4_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.023 · p80
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
stm32f4_firmware*Tracked
stm32f7_firmware*Tracked
stm32h7_firmware*Tracked
stm32l0_firmware*Tracked
stm32l1_firmware*Tracked
stm32l4_firmware*Tracked
Source databases
CVE