CVE-2019-14238: Medium severity st stm32 firmware vulnerability
On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with a debug probe via the Instruction Tightly Coupled Memory (ITCM) bus.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-14238.
What is the severity of CVE-2019-14238?
The severity of CVE-2019-14238 is medium.
How can Proprietary Code Read Out Protection (PCROP) be defeated on STMicroelectronics STM32F7 devices?
Proprietary Code Read Out Protection (PCROP) on STMicroelectronics STM32F7 devices can be defeated with a debug probe via the Instruction Tightly Coupled Memory (ITCM) bus.
What is the affected software for CVE-2019-14238?
The affected software for CVE-2019-14238 includes STMicroelectronics STM32L0 Firmware, STMicroelectronics STM32L1 Firmware, STMicroelectronics STM32F4 Firmware, STMicroelectronics STM32L4 Firmware, STMicroelectronics STM32F7 Firmware, and STMicroelectronics STM32H7 Firmware.
Are STMicroelectronics STM32L0, STM32L1, STM32F4, STM32L4, STM32F7, and STM32H7 vulnerable to CVE-2019-14238?
No, STMicroelectronics STM32L0, STM32L1, STM32F4, STM32L4, STM32F7, and STM32H7 are not vulnerable to CVE-2019-14238.
Is there any reference material for CVE-2019-14238?
Yes, you can refer to the following links for more information on CVE-2019-14238: [Whitepaper 1](https://www.usenix.org/conference/woot19/presentation/schink) and [Whitepaper 2](https://www.usenix.org/system/files/woot19-paper_schink.pdf).
What is the Common Weakness Enumeration (CWE) for CVE-2019-14238?
The Common Weakness Enumeration (CWE) for CVE-2019-14238 is CWE-287.