CVE-2020-13594
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does not properly restrict the channel map field of the connection request packet on reception, allowing attackers in radio range to cause…
Does this matter?
Lower severity and a low EPSS score (0.76%). Track it; it rarely justifies an emergency change on its own.
Description
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does not properly restrict the channel map field of the connection request packet on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.76% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- espressif/esp-idf
- Source
- cve@mitre.org
References
- https://asset-group.github.io/cves.htmlThird Party Advisory
- https://asset-group.github.io/disclosures/sweyntooth/Third Party Advisory
- https://github.com/espressif/esp32-bt-libThird Party Advisory
- https://asset-group.github.io/cves.htmlThird Party Advisory
- https://asset-group.github.io/disclosures/sweyntooth/Third Party Advisory
- https://github.com/espressif/esp32-bt-libThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.