MEDIUM · 4.6

CVE-2017-18347

Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wir...

Vulnerability Description

Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wire Debug (SWD) commands because there is a race condition between full initialization of the SWD interface and the setup of flash protection.

CVSS Score

4.6

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
StStm32F071Rb Firmware-
StStm32F071Rb-
StStm32F071V8 Firmware-
StStm32F071V8-
StStm32F071Vb Firmware-
StStm32F071Vb-
StStm32F072C8 Firmware-
StStm32F072C8-
StStm32F072Cb Firmware-
StStm32F072Cb-
StStm32F072R8 Firmware-
StStm32F072R8-
StStm32F072Rb Firmware-
StStm32F072Rb-
StStm32F072V8 Firmware-
StStm32F072V8-
StStm32F072Vb Firmware-
StStm32F072Vb-
StStm32F078Cb Firmware-
StStm32F078Cb-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-18347?

CVE-2017-18347 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wir...

How severe is CVE-2017-18347?

CVE-2017-18347 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-18347?

Check the references section above for vendor advisories and patch information. Affected products include: St Stm32F071Rb Firmware, St Stm32F071Rb, St Stm32F071V8 Firmware, St Stm32F071V8, St Stm32F071Vb Firmware.