CVE-2019-14236: Critical severity st stm32 firmware vulnerability
On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated by observing CPU registers and the effect of code/instruction execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14236?
CVE-2019-14236 is a vulnerability found on STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices where the Proprietary Code Read Out Protection (PCROP) can be defeated.
What is Proprietary Code Read Out Protection (PCROP)?
Proprietary Code Read Out Protection (PCROP) is a software IP protection method used on STMicroelectronics STM32 devices.
How does the vulnerability affect the STM32 devices?
The vulnerability affects the STM32 devices by allowing the defeat of the Proprietary Code Read Out Protection (PCROP) by observing CPU registers and the effect of code/instruction execution.
What is the severity of CVE-2019-14236?
The severity of CVE-2019-14236 is critical with a CVSS score of 9.8.
Is there a fix available for CVE-2019-14236?
Currently, there is no known fix available for CVE-2019-14236. It is recommended to follow any updates from STMicroelectronics and apply patches or mitigations as they become available.