Show filters
39 Total Results
Displaying 21-30 of 39
Sort by:
Attacker Value
Unknown

CVE-2020-20949

Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.
Attacker Value
Unknown

CVE-2020-13471

Disclosure Date: August 31, 2020 (last updated November 28, 2024)
Apex Microelectronics APM32F103 devices allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.
Attacker Value
Unknown

CVE-2020-13466

Disclosure Date: August 31, 2020 (last updated November 28, 2024)
STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.
Attacker Value
Unknown

CVE-2020-13463

Disclosure Date: August 31, 2020 (last updated February 22, 2025)
The flash memory readout protection in Apex Microelectronics APM32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.
Attacker Value
Unknown

CVE-2020-8004

Disclosure Date: April 06, 2020 (last updated November 27, 2024)
STMicroelectronics STM32F1 devices have Incorrect Access Control.
Attacker Value
Unknown

CVE-2019-14238

Disclosure Date: September 24, 2019 (last updated November 27, 2024)
On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with a debug probe via the Instruction Tightly Coupled Memory (ITCM) bus.
Attacker Value
Unknown

CVE-2019-14236

Disclosure Date: September 12, 2019 (last updated November 27, 2024)
On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated by observing CPU registers and the effect of code/instruction execution.
Attacker Value
Unknown

CVE-2018-15520

Disclosure Date: June 28, 2019 (last updated November 27, 2024)
Various Lexmark devices have a Buffer Overflow (issue 2 of 2).
0
Attacker Value
Unknown

CVE-2017-18347

Disclosure Date: September 12, 2018 (last updated November 27, 2024)
Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wire Debug (SWD) commands because there is a race condition between full initialization of the SWD interface and the setup of flash protection.
Attacker Value
Unknown

CVE-2018-12924

Disclosure Date: June 28, 2018 (last updated November 26, 2024)
Sollae Serial-Ethernet-Module and Remote-I/O-Device-Server devices have a default password of sollae for the TELNET service.
0