Successful exploitation of this vulnerability could allow an attacker to take over the device.
Rockwell Automation reports that the following products are affected by a vulnerability due to the use of STMicroelectronics STM32L4 devices:
A local code execution vulnerability exists in STMicroelectronics STM32L4 devices due to having incorrect access controls. The affected product uses the STMicroelectronics STM32L4 device and, due to the vulnerability, a malicious actor could reverse the protections that control access to the JTAG interface. If exploited, a malicious actor can take control of the device.
CVE-2020-27212 has been assigned to this vulnerability. A CVSS v3.1 base score of 7.0 has been calculated; the CVSS string vector is (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
A CVSS v4 score has also been calculated for CVE-2020-27212. A base score of 7.3 has been calculated; the CVSS string vector is (CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N).
Rockwell Automation encourages users of the affected software to apply risk mitigations if possible:
Limit physical access to authorized personnel: control room, cells/areas, control panels, and devices. Refer to Chapter 4, Strengthen the Control System of the System Security Design Guidelines.
For information on how to mitigate security risks in industrial automation control systems, Rockwell Automation encourages users to implement security practices to minimize the risk of the vulnerability.
For more information, refer to the Rockwell Automation security advisory.
Organizations are recommended to implement recommended cybersecurity strategies for proactive defense of ICS assets.





