CVE-2017-18347 - CVE House
Back to Database
Status published Medium CVE-2017-18347

Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0...

Vulnerability Description

Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wire Debug (SWD) commands because there is a race condition between full initialization of the SWD interface and the setup of flash protection.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-18347

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

stm32f071rb firmware, stm32f071v8 firmware, stm32f071vb firmware, stm32f072c8 firmware, stm32f072cb firmware, stm32f072r8 firmware, stm32f072rb firmware, stm32f072v8 firmware, stm32f072vb firmware, stm32f078cb firmware, stm32f078rb firmware, stm32f078vb firmware, stm32f091cb firmware, stm32f091cc firmware, stm32f091rb firmware, stm32f091rc firmware, stm32f091vb firmware, stm32f091vc firmware, stm32f098cc firmware, stm32f098rc firmware, stm32f098vc firmware, stm32f070c6 firmware, stm32f070cb firmware, stm32f070f6 firmware, stm32f070rb firmware, stm32f071c8 firmware, stm32f071cb firmware, stm32f051t8 firmware, stm32f058c8 firmware, stm32f058r8 firmware, stm32f058t8 firmware, stm32f051k4 firmware, stm32f051k6 firmware, stm32f051k8 firmware, stm32f051r4 firmware, stm32f051r6 firmware, stm32f051r8 firmware, stm32f042t6 firmware, stm32f048c6 firmware, stm32f048g6 firmware, stm32f048t6 firmware, stm32f051c4 firmware, stm32f051c6 firmware, stm32f051c8 firmware, stm32f042f4 firmware, stm32f042f6 firmware, stm32f042g4 firmware, stm32f042g6 firmware, stm32f042k4 firmware, stm32f042k6 firmware, stm32f038c6 firmware, stm32f038e6 firmware, stm32f038f6 firmware, stm32f038g6 firmware, stm32f038k6 firmware, stm32f042c4 firmware, stm32f042c6 firmware, stm32f031e6 firmware, stm32f031f4 firmware, stm32f031f6 firmware, stm32f031g4 firmware, stm32f031g6 firmware, stm32f031k4 firmware, stm32f030f4 firmware, stm32f030k6 firmware, stm32f030r8 firmware, stm32f030rc firmware, stm32f031c4 firmware, stm32f031c6 firmware, stm32f030c6 firmware, stm32f030c8 firmware, stm32f030cc firmware
Vulnerable Versions:
Unknown

Timeline

Official Publish: September 12th, 2018
Last Modified: September 17th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.