CVE-2021-28136

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
07/09/2021
Last modified:
09/09/2021

Description

The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range to trigger memory corruption (and consequently a crash) in ESP32 via a replayed (duplicated) LMP packet.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:* 4.4 (including)
cpe:2.3:h:espressif:esp32:-:*:*:*:*:*:*:*