CVE-2019-14236: St STM32F4 Firmware
Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.
On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated by observing CPU registers and the effect of code/instruction execution.
Affected products
- St STM32F4 Firmware: affected versions not specified
- St STM32F7 Firmware: affected versions not specified
- St STM32H7 Firmware: affected versions not specified
- St STM32L0 Firmware: affected versions not specified
- St STM32L1 Firmware: affected versions not specified
- St STM32L4 Firmware: affected versions not specified
Published 2019-09-12. Last modified 2026-06-17.