← Back

CVE-2021-28136

nvd nist
Published: Sep 7, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range to trigger memory corruption (and consequently a crash) in ESP32 via a replayed (duplicated) LMP packet.

Affected (1)

Products: Espressif: Esp Idf
1 product
Esp Idf
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.4
Running on/withPlatform Versions
Espressif
Esp32
All versions

References (8)

Source: cve@mitre.org
Technical DescriptionThird Party Advisory
Source: cve@mitre.org
ProductThird Party Advisory
Source: cve@mitre.org
ProductThird Party Advisory
Source: cve@mitre.org
ProductVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Technical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductVendor Advisory

Timeline

No history available yet.