9.8
CVSSv3

CVE-2021-42553

Published: 21/10/2022 Updated: 07/03/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions prior to 3.5.1 allows an malicious user to execute arbitrary code when the descriptor contains more endpoints than USBH_MAX_NUM_ENDPOINTS. The library is typically integrated when using a RTOS such as FreeRTOS on STM32 MCUs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

st stm32 mw usb host -

Github Repositories

Unofficial modifications for stm32_mw_usb_host

stm32_mw_usb_host-modified Unofficial modifications for stm32_mw_usb_host Middleware USB Host MCU Component Important Release v351 addresses CVE-2021-42553 Overview STM32Cube is an STMicroelectronics original initiative to ease developers' life by reducing efforts, time and cost STM32Cube covers the overall STM32 products portfolio It includes a comprehensive embedd