CVE-2017-18347

Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wire Debug (SWD) commands because there is a race condition between full initialization of the SWD interface and the setup of flash protection.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.6 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
VendorProductVersion
ststm32f071rb_firmware
-
ststm32f071v8_firmware
-
ststm32f071vb_firmware
-
ststm32f072c8_firmware
-
ststm32f072cb_firmware
-
ststm32f072r8_firmware
-
ststm32f072rb_firmware
-
ststm32f072v8_firmware
-
ststm32f072vb_firmware
-
ststm32f078cb_firmware
-
ststm32f078rb_firmware
-
ststm32f078vb_firmware
-
ststm32f091cb_firmware
-
ststm32f091cc_firmware
-
ststm32f091rb_firmware
-
ststm32f091rc_firmware
-
ststm32f091vb_firmware
-
ststm32f091vc_firmware
-
ststm32f098cc_firmware
-
ststm32f098rc_firmware
-
ststm32f098vc_firmware
-
ststm32f070c6_firmware
-
ststm32f070cb_firmware
-
ststm32f070f6_firmware
-
ststm32f070rb_firmware
-
ststm32f071c8_firmware
-
ststm32f071cb_firmware
-
ststm32f051t8_firmware
-
ststm32f058c8_firmware
-
ststm32f058r8_firmware
-
ststm32f058t8_firmware
-
ststm32f070c6_firmware
-
ststm32f051k4_firmware
-
ststm32f051k6_firmware
-
ststm32f051k8_firmware
-
ststm32f051r4_firmware
-
ststm32f051r6_firmware
-
ststm32f051r8_firmware
-
ststm32f042t6_firmware
-
ststm32f048c6_firmware
-
ststm32f048g6_firmware
-
ststm32f048t6_firmware
-
ststm32f051c4_firmware
-
ststm32f051c6_firmware
-
ststm32f051c8_firmware
-
ststm32f042f4_firmware
-
ststm32f042f6_firmware
-
ststm32f042g4_firmware
-
ststm32f042g6_firmware
-
ststm32f042k4_firmware
-
ststm32f042k6_firmware
-
ststm32f038c6_firmware
-
ststm32f038e6_firmware
-
ststm32f038f6_firmware
-
ststm32f038g6_firmware
-
ststm32f038k6_firmware
-
ststm32f042c4_firmware
-
ststm32f042c6_firmware
-
ststm32f031e6_firmware
-
ststm32f031f4_firmware
-
ststm32f031f6_firmware
-
ststm32f031g4_firmware
-
ststm32f031g6_firmware
-
ststm32f031k4_firmware
-
ststm32f030f4_firmware
-
ststm32f030k6_firmware
-
ststm32f030r8_firmware
-
ststm32f030rc_firmware
-
ststm32f031c4_firmware
-
ststm32f031c6_firmware
-
ststm32f030c6_firmware
-
ststm32f030c8_firmware
-
ststm32f030cc_firmware
-
𝑥
= Vulnerable software versions