CVE-2023-50096 is a buffer overflow vulnerability in the STMicroelectronics STSAFE-A1xx middleware (before 3.3.7), specifically within the StSafeA_ReceiveBytes function of the X-CUBE-SAFEA1 Software Package. This flaw allows for MCU code execution if an attacker can read from and write to the I2C bus, impacting user-written code derived from affected sample applications. With a CVSS score of 7.5 (HIGH), this vulnerability has an adjacent attack vector, high attack complexity, and high impacts on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.0CPE matchmatch criteria | cpe:2.3:a:st:x-cube-safea1:1.2.0:*:*:*:*:stsafe-a:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.