CVE-2021-28139
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly restrict the Feature Page upon reception of an LMP Feature Response Extended packet, allowing attackers in radio range to trigger arbitrary code execution in…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly restrict the Feature Page upon reception of an LMP Feature Response Extended packet, allowing attackers in radio range to trigger arbitrary code execution in ESP32 via a crafted Extended Features bitfield payload.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.39% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- espressif/esp-idf
- Source
- cve@mitre.org
References
- https://dl.packetstormsecurity.net/papers/general/braktooth.pdfTechnical Description, Third Party Advisory
- https://github.com/espressif/esp-idfProduct, Third Party Advisory
- https://github.com/espressif/esp32-bt-libProduct, Third Party Advisory
- https://www.espressif.com/en/products/socs/esp32Product, Vendor Advisory
- https://dl.packetstormsecurity.net/papers/general/braktooth.pdfTechnical Description, Third Party Advisory
- https://github.com/espressif/esp-idfProduct, Third Party Advisory
- https://github.com/espressif/esp32-bt-libProduct, Third Party Advisory
- https://www.espressif.com/en/products/socs/esp32Product, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.