CVE Feed

    Dashboard / CVE / CVE-2023-50096

    CVE-2023-50096

    STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect user-written code that was derived from a published sample application.

    Published:Jan 1, 2024
    Last Modified:Nov 21, 2024
    EPS:Jan 1, 2024
    EPSS Score:0.00487
    CVSS Score:7.5

    Affected Products

    Vendor
    St
    Product
    X-cube-safea1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High