External risk intelligence

STM32 USB Host Buffer Overflow Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2021-42553

This vulnerability exists in a USB host library for STM32 microcontrollers. USB host interfaces on embedded systems typically require physical interaction or proximity to connect a malicious device, making them inherently local or physical-access-dependent rather than reachable via the public internet.

Buffer Overflow

Stm32 Mw Usb Host

before 3.5.1

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This issue involves a buffer overflow vulnerability found in a USB host library used with STMicroelectronics microcontrollers. If exploited, it could allow an attacker to execute code on affected devices, particularly those using the library with real-time operating systems. The main concern is to confirm if and where this specific technology is used within our systems to understand its relevance.

  • A software flaw could allow unauthorized code execution.
  • Confirms if specific embedded technology is in use.
  • Verify technology use and assess any potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could trigger this vulnerability by sending a specially crafted USB descriptor to a device using the vulnerable USB host library. If this descriptor contains more endpoints than the system can handle, it can lead to a buffer overflow. This overflow could potentially allow an attacker to execute arbitrary code on the affected device.

  • Requires network exposure to a vulnerable device.
  • Triggered by a malicious USB descriptor.
  • Allows arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A buffer overflow in the USB host library could allow an attacker to execute arbitrary code on STM32 microcontrollers when processing USB descriptors with an excessive number of endpoints. This vulnerability is present when the library is used with an RTOS like FreeRTOS.

  • System code execution.
  • Malicious USB device attachment.
  • Unpredictable system behavior.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability resides in a USB host library for STM32 microcontrollers, often integrated with RTOS like FreeRTOS. The initial triage should focus on identifying all instances of the affected library within your STM32 MCU-based systems, assessing their network exposure and criticality, and then assigning ownership to the relevant embedded systems, firmware, or application development teams for risk-based remediation planning.

  • Firmware and embedded systems teams own the issue.
  • Verify library instances and network reachability.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is stm32_mw_usb_host?

It is a software library provided by STMicroelectronics used in embedded systems. Developers integrate this library into firmware, often alongside real-time operating systems like FreeRTOS, to enable STM32 microcontrollers to function as a USB host. It manages the complex communication protocols required to interact with connected USB devices.

What does CVE-2021-42553 mean?

This is a buffer overflow vulnerability, classified as CWE-120. It occurs when the software receives more data—specifically USB endpoints—than it has been programmed to store in its allocated memory buffer. Because the library fails to properly check the limits of these descriptors, it can lead to memory corruption, potentially allowing an attacker to run unauthorized code on the microcontroller.

How is this vulnerability triggered?

An attacker triggers this flaw by connecting a malicious device that provides a specially crafted USB descriptor to the STM32 host. The bug is triggered when that descriptor reports an endpoint count exceeding the system's predefined capacity. Simply plugging in a standard, compliant USB device does not trigger this issue.

Is this vulnerability reachable over the internet?

According to Halo Surface Signal, this vulnerability is very unlikely to be reachable via the public internet. Because the library manages physical USB host interfaces, exploitation typically requires physical interaction or proximity to the device to attach a malicious peripheral, rather than remote access over a standard network.

How should I respond to this vulnerability?

Begin by auditing your hardware inventory to identify any products or systems that utilize the STM32 MCU architecture with this specific USB library version. Once identified, coordinate with your firmware and embedded engineering teams to review the integration. The primary goal is to determine if an update to version 3.5.1 or later is required based on your device's specific deployment and physical access risks.

References