CVE-2020-13594

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
31/08/2020
Last modified:
08/09/2020

Description

The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does not properly restrict the channel map field of the connection request packet on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:* 4.2 (including)
cpe:2.3:h:espressif:esp32:-:*:*:*:*:*:*:*