HomeStCVE-2019-14236

CVE-2019-14236

CRITICAL
9.8CVSS
Published: 2019-09-12
Updated: 2024-11-21
AI Analysis

Description

On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated by observing CPU registers and the effect of code/instruction execution.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-863

Metadata

Primary Vendor
ST
Published
9/12/2019
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

st : stm32l0_firmwarest : stm32l1_firmwarest : stm32f4_firmwarest : stm32l4_firmwarest : stm32f7_firmwarest : stm32h7_firmware

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2019-14236 | CRITICAL Severity | CVEDatabase.com | CVEDatabase.com