CVE-2020-27212: High severity st stm32cubel4 vulnerability
STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by injecting a fault during the boot phase.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-27212?
CVE-2020-27212 is classified as a high-severity vulnerability due to the potential for unauthorized access to sensitive data.
How do I fix CVE-2020-27212?
To mitigate CVE-2020-27212, ensure your firmware is updated to version 1.16.1 or later, which includes security patches.
What devices are affected by CVE-2020-27212?
CVE-2020-27212 affects STM32L4 devices with STM32CubeL4 firmware versions up to 1.16.0.
What does CVE-2020-27212 exploit?
CVE-2020-27212 exploits incorrect access control during the boot phase, allowing degradation of flash read-out protection.
Can CVE-2020-27212 lead to data exposure?
Yes, CVE-2020-27212 can potentially expose sensitive data by allowing limited access to the debug interface.