LiveActive security incident?Get immediate response
CVE Record

CVE-2020-27212: STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control.

STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by injecting a fault during the boot phase.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This issue affects STMicroelectronics STM32L4 devices where read-out protection is intended to block debug access. The cited CVE says a boot-time fault can reduce protection from the strongest level to a weaker one. Business risk is mainly loss of firmware, embedded secrets, or product IP from devices an attacker can physically access.

Executive priority

Prioritize review for fielded devices that store valuable IP, credentials, or customer-sensitive material on STM32L4 hardware. Urgency is lower for devices kept in controlled facilities or not relying on RDP for sensitive protection.

Technical view

CVE-2020-27212 describes incorrect access control in STM32L4 devices through 2020-10-19. The RDP Level 2 debug lock can be downgraded to Level 1 through boot-phase fault injection. Sources do not provide CVSS, a vendor fix, affected CPEs, or confirmed exploitation details.

Likely exposure

Exposure is most plausible for products containing STM32L4 microcontrollers that rely on RDP Level 2 to protect firmware or secrets. This is not described as a remote network vulnerability; physical access and fault-injection capability appear central.

Exploitation context

The source bundle does not show CISA KEV listing or active exploitation. The described attack is specialized hardware fault injection during boot, so practical risk depends on device accessibility, attacker resources, and whether valuable secrets are protected only by RDP.

Researcher notes

Evidence is limited to the CVE description and linked public research references. No CVSS, CWE, patch version, detailed affected CPE list, or exploitation-in-the-wild evidence is provided in the bundle. Treat conclusions about exploit practicality as constrained by physical-access assumptions.

Mitigation direction

  • Identify products and boards using STM32L4 devices.
  • Check STMicroelectronics guidance, errata, and lifecycle recommendations.
  • Review whether RDP Level 2 protects firmware, keys, or credentials.
  • Strengthen physical tamper resistance for field-accessible devices.
  • Avoid relying on RDP alone for high-value secrets.
  • Plan remediation with the device or silicon vendor.

Validation and detection

  • Inventory STM32L4 parts and firmware protection settings.
  • Confirm whether affected devices were produced through 2020-10-19.
  • Review product threat models for physical possession scenarios.
  • Check vendor advisories before making hardware or firmware changes.
  • Assess whether exposed firmware contains reusable secrets.
  • Document compensating controls and residual physical-access risk.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-27212 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.