CVE-2020-27212: High severity st stm32cubel4 vulnerability

Published May 21, 2021
·
Updated

STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by injecting a fault during the boot phase.

Affected Software

95 affected components
ST Stm32cubel4 Firmware<=1.16.0
ST Stm32l412c8
ST Stm32l412cb
ST Stm32l412k8
ST Stm32l412kb
ST Stm32l412r8
ST Stm32l412rb
ST Stm32l412t8
ST Stm32l412tb
ST Stm32l422cb
ST Stm32l422kb
ST Stm32l422rb
ST Stm32l422tb
ST Stm32l431cb
ST Stm32l431cc
ST Stm32l431kb
ST Stm32l431kc
ST Stm32l431rb
ST Stm32l431rc
ST Stm32l431vc
ST Stm32l432kb
ST Stm32l432kc
ST Stm32l433cb
ST Stm32l433cc
ST Stm32l433rb
ST Stm32l433rc
ST Stm32l433vc
ST Stm32l442kc
ST Stm32l443cc
ST Stm32l443rc
ST Stm32l443vc
ST Stm32l451cc
ST Stm32l451ce
ST Stm32l451rc
ST Stm32l451re
ST Stm32l451vc
ST Stm32l451ve
ST Stm32l452cc
ST Stm32l452ce
ST Stm32l452rc
ST Stm32l452re
ST Stm32l452vc
ST Stm32l452ve
ST Stm32l462ce
ST Stm32l462re
ST Stm32l462ve
ST Stm32l471qe
ST Stm32l471qg
ST Stm32l471re
ST Stm32l471rg
ST Stm32l471ve
ST Stm32l471vg
ST Stm32l471ze
ST Stm32l471zg
ST Stm32l475rc
ST Stm32l475re
ST Stm32l475rg
ST Stm32l475vc
ST Stm32l475ve
ST Stm32l475vg
ST Stm32l476je
ST Stm32l476jg
ST Stm32l476me
ST Stm32l476mg
ST Stm32l476qe
ST Stm32l476qg
ST Stm32l476rc
ST Stm32l476re
ST Stm32l476rg
ST Stm32l476vc
ST Stm32l476ve
ST Stm32l476vg
ST Stm32l476ze
ST Stm32l476zg
ST Stm32l486jg
ST Stm32l486qg
ST Stm32l486rg
ST Stm32l486vg
ST Stm32l486zg
ST Stm32l496ae
ST Stm32l496ag
ST Stm32l496qe
ST Stm32l496qg
ST Stm32l496re
ST Stm32l496rg
ST Stm32l496ve
ST Stm32l496vg
ST Stm32l496wg
ST Stm32l496ze
ST Stm32l496zg
ST Stm32l4a6ag
ST Stm32l4a6qg
ST Stm32l4a6rg
ST Stm32l4a6vg
ST Stm32l4a6zg

Event History

May 21, 2021
CVE Published
via MITRE·11:48 AM
Data Sourced
via MITRE·11:48 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2020-27212?

CVE-2020-27212 is classified as a high-severity vulnerability due to the potential for unauthorized access to sensitive data.

2

How do I fix CVE-2020-27212?

To mitigate CVE-2020-27212, ensure your firmware is updated to version 1.16.1 or later, which includes security patches.

3

What devices are affected by CVE-2020-27212?

CVE-2020-27212 affects STM32L4 devices with STM32CubeL4 firmware versions up to 1.16.0.

4

What does CVE-2020-27212 exploit?

CVE-2020-27212 exploits incorrect access control during the boot phase, allowing degradation of flash read-out protection.

5

Can CVE-2020-27212 lead to data exposure?

Yes, CVE-2020-27212 can potentially expose sensitive data by allowing limited access to the debug interface.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203