CVE-2020-13595

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/08/2020
Last modified:
08/09/2020

Description

The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a reachable assertion on the host stack when receiving a packet with an MIC failure. An attacker within radio range can silently trigger the assertion (which disables the target's BLE stack) by sending a crafted sequence of BLE packets.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:* 4.0.0 (including) 4.2 (including)
cpe:2.3:h:espressif:esp32:-:*:*:*:*:*:*:*