CVE-2023-35818
6.8
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD
Description
An issue was discovered on Espressif ESP32 3.0 (ESP32_rev300 ROM) devices. An EMFI attack on ECO3 provides the attacker with a capability to influence the PC value at the CPU context level, regardless of Secure Boot and Flash Encryption status. By using this capability, the attacker can exploit another behavior in the chip to gain unauthorized access to the ROM download mode. Access to ROM download mode may be further exploited to read the encrypted flash content in cleartext format or execute stub code.
Affected (44)
Products: Espressif: Esp32 D0wd V3 Firmware, Esp32 D0wdr2 V3 Firmware, Esp32 U4wdh Firmware, Esp32 Pico V3 Firmware, Esp32 Pico V3 02 Firmware, Esp32 Pico D4 Firmware, Esp32 Wroom 32e Firmware, Esp32 Wroom 32ue Firmware, Esp32 Wroom Da Firmware, Esp32 Wrover E Firmware, Esp32 Wrover Ie Firmware, Esp32 Mini 1 Firmware, Esp32 Mini 1u Firmware, Esp32 Pico Mini 02 Firmware, Esp32 Pico Mini 02u Firmware, Esp32 Pico V3 Zero Firmware, Esp32 Devkitc Firmware, Esp32 Devkitm 1 Firmware, Esp32 Pico Kit Firmware, Esp32 Pico V3 Zero Devkit Firmware, Esp Eye Firmware, Esp32 Vaquita Dspg Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 D0wd V3 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 D0wdr2 V3 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 U4wdh | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Pico V3 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Pico V3 02 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Pico D4 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Wroom 32e | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Wroom 32ue | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Wroom Da | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Wrover E | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Wrover Ie | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Mini 1 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Mini 1u | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Pico Mini 02 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Pico Mini 02u | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Pico V3 Zero | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Devkitc | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Devkitm 1 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Pico Kit | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Pico V3 Zero Devkit | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp Eye | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Espressif Esp32 Vaquita Dspg | All versions |
References (4)
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.