{"id":"CVE-2021-42553","title":"A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker to execute arbitrary code when the descriptor contains more endpoints than USBH_MAX_NUM_ENDPOINTS","summary":"A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker to execute arbitrary code when the descriptor contains more endpoints than USBH_MAX_NUM_ENDPOINTS. The library is typi…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-120","CWE-120"],"vendor":"st","product":"stm32_mw_usb_host","affected":["stm32_mw_usb_host < 3.5.1"],"patched":["stm32_mw_usb_host 3.5.1"],"published":"2022-10-21","updated":"2026-10-08","sourceUpdated":"2026-10-08T18:23:29.090","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-42553","references":[{"url":"https://github.com/STMicroelectronics/stm32_mw_usb_host","label":"vulnerability@ncsc.ch"},{"url":"https://github.com/STMicroelectronics/stm32_mw_usb_host/pull/4","label":"vulnerability@ncsc.ch"},{"url":"https://github.com/STMicroelectronics/stm32_mw_usb_host","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/STMicroelectronics/stm32_mw_usb_host/pull/4","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.0106,"epssPercentile":0.63481,"ingestedAt":"2026-10-08T18:58:11.290Z","slug":"CVE-2021-42553","body":"## Overview\n\nA buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker to execute arbitrary code when the descriptor contains more endpoints than USBH_MAX_NUM_ENDPOINTS. The library is typically integrated when using a RTOS such as FreeRTOS on STM32 MCUs.\n\n## Affected\n\n- `stm32_mw_usb_host < 3.5.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `stm32_mw_usb_host 3.5.1`","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":37.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}