CVE-2017-18347: Race Condition

Published Sep 12, 2018
·
Updated

Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wire Debug (SWD) commands because there is a race condition between full initialization of the SWD interface and the setup of flash protection.

Affected Software

144 affected components
ST Stm32f071rb Firmware
ST Stm32f071rb
ST Stm32f071v8 Firmware
ST Stm32f071v8
ST Stm32f071vb Firmware
ST Stm32f071vb
ST Stm32f072c8 Firmware
ST Stm32f072c8
ST Stm32f072cb Firmware
ST Stm32f072cb
ST Stm32f072r8 Firmware
ST Stm32f072r8
ST Stm32f072rb Firmware
ST Stm32f072rb
ST Stm32f072v8 Firmware
ST Stm32f072v8
ST Stm32f072vb Firmware
ST Stm32f072vb
ST Stm32f078cb Firmware
ST Stm32f078cb
ST Stm32f078rb Firmware
ST Stm32f078rb
ST Stm32f078vb Firmware
ST Stm32f078vb
ST Stm32f091cb Firmware
ST Stm32f091cb
ST Stm32f091cc Firmware
ST Stm32f091cc
ST Stm32f091rb Firmware
ST Stm32f091rb
ST Stm32f091rc Firmware
ST Stm32f091rc
ST Stm32f091vb Firmware
ST Stm32f091vb
ST Stm32f091vc Firmware
ST Stm32f091vc
ST Stm32f098cc Firmware
ST Stm32f098cc
ST Stm32f098rc Firmware
ST Stm32f098rc
ST Stm32f098vc Firmware
ST Stm32f098vc
ST Stm32f070c6 Firmware
ST Stm32f070c6
ST Stm32f070cb Firmware
ST Stm32f070cb
ST Stm32f070f6 Firmware
ST Stm32f070f6
ST Stm32f070rb Firmware
ST Stm32f070rb
ST Stm32f071c8 Firmware
ST Stm32f071c8
ST Stm32f071cb Firmware
ST Stm32f071cb
ST Stm32f051t8 Firmware
ST Stm32f051t8
ST Stm32f058c8 Firmware
ST Stm32f058c8
ST Stm32f058r8 Firmware
ST Stm32f058r8
ST Stm32f058t8 Firmware
ST Stm32f058t8
ST Stm32f051k4 Firmware
ST Stm32f051k4
ST Stm32f051k6 Firmware
ST Stm32f051k6
ST Stm32f051k8 Firmware
ST Stm32f051k8
ST Stm32f051r4 Firmware
ST Stm32f051r4
ST Stm32f051r6 Firmware
ST Stm32f051r6
ST Stm32f051r8 Firmware
ST Stm32f051r8
ST Stm32f042t6 Firmware
ST Stm32f042t6
ST Stm32f048c6 Firmware
ST Stm32f048c6
ST Stm32f048g6 Firmware
ST Stm32f048g6
ST Stm32f048t6 Firmware
ST Stm32f048t6
ST Stm32f051c4 Firmware
ST Stm32f051c4
ST Stm32f051c6 Firmware
ST Stm32f051c6
ST Stm32f051c8 Firmware
ST Stm32f051c8
ST Stm32f042f4 Firmware
ST Stm32f042f4
ST Stm32f042f6 Firmware
ST Stm32f042f6
ST Stm32f042g4 Firmware
ST Stm32f042g4
ST Stm32f042g6 Firmware
ST Stm32f042g6
ST Stm32f042k4 Firmware
ST Stm32f042k4
ST Stm32f042k6 Firmware
ST Stm32f042k6
ST Stm32f038c6 Firmware
ST Stm32f038c6
ST Stm32f038e6 Firmware
ST Stm32f038e6
ST Stm32f038f6 Firmware
ST Stm32f038f6
ST Stm32f038g6 Firmware
ST Stm32f038g6
ST Stm32f038k6 Firmware
ST Stm32f038k6
ST Stm32f042c4 Firmware
ST Stm32f042c4
ST Stm32f042c6 Firmware
ST Stm32f042c6
ST Stm32f031e6 Firmware
ST Stm32f031e6
ST Stm32f031f4 Firmware
ST Stm32f031f4
ST Stm32f031f6 Firmware
ST Stm32f031f6
ST Stm32f031g4 Firmware
ST Stm32f031g4
ST Stm32f031g6 Firmware
ST Stm32f031g6
ST Stm32f031k4 Firmware
ST Stm32f031k4
ST Stm32f030f4 Firmware
ST Stm32f030f4
ST Stm32f030k6 Firmware
ST Stm32f030k6
ST Stm32f030r8 Firmware
ST Stm32f030r8
ST Stm32f030rc Firmware
ST Stm32f030rc
ST Stm32f031c4 Firmware
ST Stm32f031c4
ST Stm32f031c6 Firmware
ST Stm32f031c6
ST Stm32f030c6 Firmware
ST Stm32f030c6
ST Stm32f030c8 Firmware
ST Stm32f030c8
ST Stm32f030cc Firmware
ST Stm32f030cc

Event History

Sep 12, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2017-18347?

CVE-2017-18347 is considered a high-severity vulnerability due to its potential to allow unauthorized access to sensitive firmware.

2

How do I fix CVE-2017-18347?

To remediate CVE-2017-18347, implement firmware updates provided by STMicroelectronics that address the reported vulnerability.

3

What devices are affected by CVE-2017-18347?

CVE-2017-18347 affects specific STMicroelectronics STM32F0 series devices with improperly implemented RDP Level 1.

4

What are the consequences of exploiting CVE-2017-18347?

Exploitation of CVE-2017-18347 can lead to unauthorized extraction of device firmware, exposing sensitive information and allowing further attacks.

5

Is CVE-2017-18347 a remote or local vulnerability?

CVE-2017-18347 is a local vulnerability that requires physical access to the device to exploit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203