CVE-2017-18347: Race Condition
Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wire Debug (SWD) commands because there is a race condition between full initialization of the SWD interface and the setup of flash protection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18347?
CVE-2017-18347 is considered a high-severity vulnerability due to its potential to allow unauthorized access to sensitive firmware.
How do I fix CVE-2017-18347?
To remediate CVE-2017-18347, implement firmware updates provided by STMicroelectronics that address the reported vulnerability.
What devices are affected by CVE-2017-18347?
CVE-2017-18347 affects specific STMicroelectronics STM32F0 series devices with improperly implemented RDP Level 1.
What are the consequences of exploiting CVE-2017-18347?
Exploitation of CVE-2017-18347 can lead to unauthorized extraction of device firmware, exposing sensitive information and allowing further attacks.
Is CVE-2017-18347 a remote or local vulnerability?
CVE-2017-18347 is a local vulnerability that requires physical access to the device to exploit.