ST develops a broad portfolio of embedded real-time operating systems and microcontroller firmware development kits, particularly across its X-CUBE-AZRTOS platform family serving ARM-based embedded systems. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, though the exposure reflects the inherent complexity of embedded firmware development including buffer overflows, integer wraparound conditions, cryptographic signature verification issues, and injection vulnerabilities. The recurring products center on real-time OS implementations for various microcontroller architectures, and the weakness classes cluster around memory-safety and cryptographic robustness—the core attack surface in deeply embedded systems where patch cycles are lengthy and deployment is long-lived. Defenders should prioritize inventory of systems running affected versions and assess update feasibility within operational constraints; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by St over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42553CRITICAL A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker to execute arbitrary code when the descriptor contains more e | Oct 21, 2022 | 9.8 | 32 | NO | NO |
CVE-2019-14236CRITICAL On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeat | Sep 12, 2019 | 9.8 | 30 | NO | NO |
CVE-2024-45064CRITICAL A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets ca | Apr 2, 2025 | 9.8 | 24 | NO | NO |
CVE-2024-50596HIGH An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to | Apr 2, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-50595HIGH An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests | Apr 2, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-50384HIGH A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead t | Apr 2, 2025 | 7.5 | 22 | NO | NO |
CVE-2023-50096HIGH STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA | Jan 1, 2024 | 7.5 | 22 | NO | NO |
CVE-2021-34262MEDIUM A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code. | Jul 22, 2021 | 6.8 | 22 | NO | NO |
CVE-2021-34260MEDIUM A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code. | Jul 22, 2021 | 6.8 | 22 | NO | NO |
CVE-2021-34259MEDIUM A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code. | Jul 22, 2021 | 6.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by St.
Media articles that mention a CVE ID that affects a product developed by St — matched by CVE ID, not by vendor name.