CVE-2020-27212: St STM32CUBEL4 Firmware

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by injecting a fault during the boot phase.

Affected products

  • St STM32CUBEL4 Firmware: up to and including 1.16.0

Published 2021-05-21. Last modified 2026-06-17.