HomeStCVE-2021-42553

CVE-2021-42553

MEDIUM
6.8CVSS
Published: 2022-10-21
Updated: 2025-05-07
AI Analysis

Description

A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker to execute arbitrary code when the descriptor contains more endpoints than USBH_MAX_NUM_ENDPOINTS. The library is typically integrated when using a RTOS such as FreeRTOS on STM32 MCUs.

CVSS Metrics

Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
physical
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-120CWE-120

Metadata

Primary Vendor
ST
Published
10/21/2022
Last Modified
5/7/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

st : stm32_mw_usb_host

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2021-42553 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com