← Back

CVE-2026-45328

nvd nist
Published: Jun 10, 2026Modified: Jun 11, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.0 / Impact: 6.0
Source: NVD

Description

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c that bridge calls from the user application (i.e. the REE) to TEE-protected hardware peripherals (AES, SHA, ECC, HMAC, SPI, MMU, WDT) and to the security feature like attestation, OTA updates, secure storage. This issue has been patched in versions 5.5.5 and 6.0.1.

Affected (2)

Products: Espressif: Esp Idf
1 product
Esp Idf
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Espressif
Version 5.5.4
Version 6.0

Timeline

No history available yet.