Skip to main content

Vendor/product archive

espressif / esp32 CVEs

Beta · best-effort

8 CVEs tagged to espressif / esp320 Critical, 4 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2021-28139

Published Sep 7, 2021

The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly restrict the Feature Page upon reception of an LMP Feature Response Extended packet, al…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-28136

Published Sep 7, 2021

The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing p…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34173

Published Jul 14, 2021

An attacker can cause a Denial of Service and kernel panic in v4.2 and earlier versions of Espressif esp32 via a malformed beacon csa frame. The device requires a reboot to recove…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13595

Published Aug 31, 2020

The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13594

Published Aug 31, 2020

The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does not properly restrict the channel map field of the connectio…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1