Description
STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by injecting a fault during the boot phase.
References (3)
Core 3
Core References
Third Party Advisory x_refsource_misc
https://www.aisec.fraunhofer.de/en/FirmwareProtection.html
Third Party Advisory x_refsource_misc
https://eprint.iacr.org/2021/640
Third Party Advisory x_refsource_misc
https://www.aisec.fraunhofer.de/de/das-institut/wissenschaftliche-exzellenz/security-and-trust-in-open-source-security-tokens.html
Scores
CVSS v3
7.0
EPSS
0.0034
EPSS Percentile
26.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-74
Status
published
Products (1)
st/stm32cubel4_firmware
< 1.16.0
Published
May 21, 2021
Tracked Since
Feb 18, 2026