Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

St

First CVE: Jul 2, 2003Active for: 23 yearsTotal CVEs: 29
16.9
VTI Score
Low

ST develops a broad portfolio of embedded real-time operating systems and microcontroller firmware development kits, particularly across its X-CUBE-AZRTOS platform family serving ARM-based embedded systems. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, though the exposure reflects the inherent complexity of embedded firmware development including buffer overflows, integer wraparound conditions, cryptographic signature verification issues, and injection vulnerabilities. The recurring products center on real-time OS implementations for various microcontroller architectures, and the weakness classes cluster around memory-safety and cryptographic robustness—the core attack surface in deeply embedded systems where patch cycles are lengthy and deployment is long-lived. Defenders should prioritize inventory of systems running affected versions and assess update feasibility within operational constraints; live severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by St over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 2, 2003
23 years ago
Most Recent CVE
Apr 2, 2025
478 days ago

Products(305 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-42553CRITICAL
A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker to execute arbitrary code when the descriptor contains more e
Oct 21, 20229.832NONO
CVE-2019-14236CRITICAL
On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeat
Sep 12, 20199.830NONO
CVE-2024-45064CRITICAL
A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets ca
Apr 2, 20259.824NONO
CVE-2024-50596HIGH
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to
Apr 2, 20257.522NONO
CVE-2024-50595HIGH
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests
Apr 2, 20257.522NONO
CVE-2024-50384HIGH
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead t
Apr 2, 20257.522NONO
CVE-2023-50096HIGH
STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA
Jan 1, 20247.522NONO
CVE-2021-34262MEDIUM
A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.
Jul 22, 20216.822NONO
CVE-2021-34260MEDIUM
A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.
Jul 22, 20216.822NONO
CVE-2021-34259MEDIUM
A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.
Jul 22, 20216.822NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
59%
31%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (13.8%)
Network12 (41.4%)
Unknown1 (3.4%)
Physical10 (34.5%)
Adjacent Network2 (6.9%)
Attack Complexity
Low24 (82.8%)
High4 (13.8%)
Unknown1 (3.4%)
User Interaction
None28 (96.6%)
Unknown1 (3.4%)
Required0 (0.0%)
Privileges Required
Low3 (10.3%)
High0 (0.0%)
None25 (86.2%)
Unknown1 (3.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by St.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by St — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For St's Products

View all 3 CNAs →

Top CWEs