Vulnerabilities > ST > High

DATE CVE VULNERABILITY TITLE RISK
2024-01-01 CVE-2023-50096 Classic Buffer Overflow vulnerability in ST X-Cube-Safea1 1.2.0
STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus.
high complexity
st CWE-120
7.5
2020-08-31 CVE-2020-13466 Unspecified vulnerability in ST Stm32F103 Firmware
STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.
local
low complexity
st
7.2
2019-09-12 CVE-2019-14236 Incorrect Authorization vulnerability in ST products
On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated by observing CPU registers and the effect of code/instruction execution.
network
low complexity
st CWE-863
7.5