11 STM32F1 Interrupt Jigsaw
RDP Level 1 of the STM32 series, in which JTAG debugging is allowed but immediately disconnects flash memory, is an appealing target for memory extraction exploits. The STM32F1 series does not seem to be vulnerable to Obermaier’s STM32F0 exploit from Chapter 10 or the DFU bootloader exploit from Chapter 2, but in this chapter we will cover a different vulnerability, first described in Schink and Obermaier (2020) for the STM32F1 and shortly after in Obermaier, Schink, and Moczek (2020) for two of its clones, the APM32F103 and CKS32F103. As a bonus, the STM32F1 series does not support RDP Level 2, so it’s possible that all parts in the series are vulnerable.
When protections are enabled, flash memory is disconnected ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access