CVE-2021-34260: Buffer Overflow
Published Jul 22, 2021
·Updated
A buffer overflow vulnerability in the USBHParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.
Affected Software
2 affected components
ST STM32Cube Middleware<=1.8.0
ST Stm32h7b3
Event History
Jul 22, 2021
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-34260?
The severity of CVE-2021-34260 is medium.
2
How can an attacker exploit CVE-2021-34260?
An attacker can exploit CVE-2021-34260 by triggering a buffer overflow in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below, allowing them to execute arbitrary code.
3
What is the affected software of CVE-2021-34260?
The affected software of CVE-2021-34260 is STMicroelectronics STM32Cube Middleware v1.8.0 and below.
4
Is STMicroelectronics STM32h7b3 vulnerable to CVE-2021-34260?
No, STMicroelectronics STM32h7b3 is not vulnerable to CVE-2021-34260.
5
Is there a fix available for CVE-2021-34260?
Yes, it is recommended to update to a version of STMicroelectronics STM32Cube Middleware above 1.8.0 to fix CVE-2021-34260.