CVE-2021-34259: Buffer Overflow
Published Jul 22, 2021
·Updated
A buffer overflow vulnerability in the USBHParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.
Affected Software
2 affected components
ST STM32Cube Middleware<=1.8.0
ST Stm32h7b3
Event History
Jul 22, 2021
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-34259.
2
What is the title of the vulnerability?
The title of the vulnerability is 'A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.'
3
What is the affected software?
The affected software is STMicroelectronics STM32Cube Middleware v1.8.0 and below.
4
How severe is the vulnerability?
The severity of the vulnerability is medium (CVSS score: 6.8).
5
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability to execute arbitrary code.