CVE-2021-42553
Published: Oct 21, 2022
Modified: May 7, 2025
CVSS v3.1
6.8
Description
A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker to execute arbitrary code when the descriptor contains more endpoints than USBH_MAX_NUM_ENDPOINTS. The library is typically integrated when using a RTOS such as FreeRTOS on STM32 MCUs.
| Vendor | Product | Versions |
|---|---|---|
STMicroelectronics STM32Cube | STM32 USB Host Library | affected all - < 3.5.1 |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now