Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-42553

Опубликовано: 21 окт. 2022
Источник: nvd
CVSS3: 6.8
CVSS3: 9.8
EPSS Низкий

Описание

A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker to execute arbitrary code when the descriptor contains more endpoints than USBH_MAX_NUM_ENDPOINTS. The library is typically integrated when using a RTOS such as FreeRTOS on STM32 MCUs.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:st:stm32_mw_usb_host:-:*:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.01415
Низкий

6.8 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-120
CWE-120

Связанные уязвимости

CVSS3: 6.8
ubuntu
больше 3 лет назад

A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker to execute arbitrary code when the descriptor contains more endpoints than USBH_MAX_NUM_ENDPOINTS. The library is typically integrated when using a RTOS such as FreeRTOS on STM32 MCUs.

CVSS3: 9.8
github
больше 3 лет назад

A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics allows an attacker to execute arbitrary code when the descriptor contains more endpoints than USBH_MAX_NUM_ENDPOINTS. The library is typically integrated when using a RTOS such as FreeRTOS on STM32 MCUs.

EPSS

Процентиль: 80%
0.01415
Низкий

6.8 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-120
CWE-120