LiveActive security incident?Get immediate response
CVE Record

CVE-2017-18347: Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically pres...

Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wire Debug (SWD) commands because there is a race condition between full initialization of the SWD interface and the setup of flash protection.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This issue weakens firmware readout protection on STM32F0 devices. A person with physical access may be able to extract protected firmware despite RDP Level 1. The main business risk is loss of embedded intellectual property, keys, or proprietary logic from deployed devices.

Executive priority

Prioritize if your organization ships STM32F0-based products into customer, field, or adversary-accessible environments. The urgency is lower for lab-only devices under trusted physical control.

Technical view

CVE-2017-18347 describes incorrect access control in STM32F0 RDP Level 1. The source states a race condition exists between SWD interface initialization and flash protection setup, enabling protected firmware extraction through a special SWD command sequence by a physically present attacker.

Likely exposure

Exposure is likely limited to products using STMicroelectronics STM32F0 series devices with RDP Level 1 as a firmware confidentiality control. It is not described as remotely exploitable. Risk rises for devices deployed in untrusted physical locations.

Exploitation context

The provided sources reference public research from WOOT 2017 and Fraunhofer AISEC. The CVE source bundle does not identify active exploitation, and KEV status is false. Exploitation requires physical presence and SWD access context.

Researcher notes

The source bundle lacks CVSS, CWE, affected version granularity, and named vendor remediation. Treat product and revision scoping as incomplete until verified against STMicroelectronics guidance and the referenced research materials.

Mitigation direction

  • Check STMicroelectronics guidance for affected revisions and approved mitigations.
  • Do not rely on RDP Level 1 alone for sensitive firmware confidentiality.
  • Review whether firmware contains keys, credentials, or proprietary algorithms.
  • Strengthen physical protections around debug access and device enclosure.
  • Plan redesign or replacement if vendor guidance requires hardware changes.

Validation and detection

  • Inventory products using STM32F0 series microcontrollers.
  • Confirm whether RDP Level 1 is enabled on deployed devices.
  • Assess whether SWD pins are physically reachable on fielded hardware.
  • Review firmware contents for embedded secrets or sensitive IP.
  • Track STMicroelectronics advisories for exact affected devices and remedies.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2017-18347 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.