← Back

Espressif

espressif

44 CVEs • 67 products

Products (67)

Click to collapse
Toggle
Esp Idf
esp-idf
Arduino Esp32
arduino-esp32
Esptool
esptool
Esp Now
esp-now
Esp32 D0wd
esp32-d0wd
Esp32 D2wd
esp32-d2wd
Esp32 S0wd
esp32-s0wd
Esp32 Pico D4
esp32-pico-d4
Esp32
esp32
Esp8266
esp8266
Esp32 D0wd V3
esp32-d0wd-v3
Esp32 U4wdh
esp32-u4wdh
Esp32 Pico V3
esp32-pico-v3
Esp32 Mini 1
esp32-mini-1
Esp32 Mini 1u
esp32-mini-1u
Esp32 Devkitc
esp32-devkitc
Esp Eye
esp-eye
Esp32 C3
esp32-c3
Esp32 C6
esp32-c6
Esp32 H2
esp32-h2
Esp32 S2
esp32-s2
Esp32 S3
esp32-s3

CVEs (44)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Espressif
1Esp Idf
Jun 17, 2026
Mar 13, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a previous connection session, creating an opportunity...Show more
Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a previous connection session, creating an opportunity for attackers to execute security bypass attacks.Show less
1Espressif
1Esp32 Firmware
Jun 17, 2026
Mar 8, 2025
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).
1Espressif
1Esp Idf
Jun 17, 2026
Nov 7, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel packet.
1Espressif
1Esp Idf
Jun 17, 2026
Oct 17, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to obtain sensitive information via the externalId component.
1Espressif
1Esp Now
Jun 17, 2026
Sep 12, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered in the implementation of the ESP-NOW because the caches is not differentiated by message types, it...Show more
ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered in the implementation of the ESP-NOW because the caches is not differentiated by message types, it is a single, shared resource for all kinds of messages, whether they are broadcast or unicast, and regardless of whether they are ciphertext or plaintext. This can result an attacker to clear the cache of its legitimate entries, there by creating an opportunity to re-inject previously captured packets. This vulnerability is fixed in 2.5.2.Show less
1Espressif
1Esp Idf
Jun 17, 2026
May 14, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component.
1Espressif
1Esp Idf
Jun 17, 2026
Mar 25, 2024
N/A· v4
5.7 MEDIUM· v3
N/A· v2
ESP-IDF is the development framework for Espressif SoCs supported on Windows, Linux and macOS. A Time-of-Check to Time-of-Use (TOCTOU) vulnerability was discovered in the implementation of the ESP-IDF bootloader which co...Show more
ESP-IDF is the development framework for Espressif SoCs supported on Windows, Linux and macOS. A Time-of-Check to Time-of-Use (TOCTOU) vulnerability was discovered in the implementation of the ESP-IDF bootloader which could allow an attacker with physical access to flash of the device to bypass anti-rollback protection. Anti-rollback prevents rollback to application with security version lower than one programmed in eFuse of chip. This attack can allow to boot past (passive) application partition having lower security version of the same device even in the presence of the flash encryption scheme. The attack requires carefully modifying the flash contents after the anti-rollback checks have been performed by the bootloader (before loading the application). The vulnerability is fixed in 4.4.7 and 5.2.1.Show less
1Espressif
1Esptool
Jun 17, 2026
Nov 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm.
1Espressif
22Esp Eye Firmware
Esp32 D0wd V3 FirmwareEsp32 D0wdr2 V3 Firmware+19 more
Jun 17, 2026
Jul 17, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
An issue was discovered on Espressif ESP32 3.0 (ESP32_rev300 ROM) devices. An EMFI attack on ECO3 provides the attacker with a capability to influence the PC value at the CPU context level, regardless of Secure Boot and...Show more
An issue was discovered on Espressif ESP32 3.0 (ESP32_rev300 ROM) devices. An EMFI attack on ECO3 provides the attacker with a capability to influence the PC value at the CPU context level, regardless of Secure Boot and Flash Encryption status. By using this capability, the attacker can exploit another behavior in the chip to gain unauthorized access to the ROM download mode. Access to ROM download mode may be further exploited to read the encrypted flash content in cleartext format or execute stub code.Show less
1Espressif
1Esp Idf
Jun 17, 2026
Jun 25, 2022
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a memory corruption vulnerability can be triggered during provisioning, because there is no check for...Show more
ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a memory corruption vulnerability can be triggered during provisioning, because there is no check for the `SegN` field of the Transaction Start PDU. This can result in memory corruption related attacks and potentially attacker gaining control of the entire system. Patch commits are available on the 4.1, 4.2, 4.3 and 4.4 branches and users are recommended to upgrade. The upgrade is applicable for all applications and users of `ESP-BLE-MESH` component from `ESP-IDF`. As it is implemented in the Bluetooth Mesh stack, there is no workaround for the user to fix the application layer without upgrading the underlying firmware.Show less
1Espressif
1Esp Idf
Jun 17, 2026
Sep 7, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly restrict the Feature Page upon reception of an LMP Feature Response Extended packet, allowing attackers in radio range to trigge...Show more
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly restrict the Feature Page upon reception of an LMP Feature Response Extended packet, allowing attackers in radio range to trigger arbitrary code execution in ESP32 via a crafted Extended Features bitfield payload.Show less
1Espressif
1Esp Idf
Jun 17, 2026
Sep 7, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range...Show more
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range to trigger memory corruption (and consequently a crash) in ESP32 via a replayed (duplicated) LMP packet.Show less
1Espressif
1Esp Idf
Jun 17, 2026
Sep 7, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (...Show more
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (crash) in ESP32 by flooding the target device with LMP Feature Response data.Show less
1Espressif
1Esp32 Firmware
Jun 17, 2026
Jul 14, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An attacker can cause a Denial of Service and kernel panic in v4.2 and earlier versions of Espressif esp32 via a malformed beacon csa frame. The device requires a reboot to recover.
1Espressif
1Esp Idf
Jun 17, 2026
Jan 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x through 4.0.1 has a Buffer Overflow in BluFi provisioning in btc_blufi_recv_handler function in blufi_p...Show more
Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x through 4.0.1 has a Buffer Overflow in BluFi provisioning in btc_blufi_recv_handler function in blufi_prf.c. An attacker can send a crafted BluFi protocol Write Attribute command to characteristic 0xFF01. With manipulated packet fields, there is a buffer overflow.Show less
1Espressif
1Esp Idf
Jun 17, 2026
Aug 31, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a reachable assertion on the host stack whe...Show more
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a reachable assertion on the host stack when receiving a packet with an MIC failure. An attacker within radio range can silently trigger the assertion (which disables the target's BLE stack) by sending a crafted sequence of BLE packets.Show less
1Espressif
1Esp Idf
Jun 17, 2026
Aug 31, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does not properly restrict the channel map field of the connection request packet on reception, allowing a...Show more
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does not properly restrict the channel map field of the connection request packet on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.Show less
1Espressif
3Esp Idf
Esp8266 Nonos SdkEsp8266 Rtos Sdk
Jun 17, 2026
Jul 23, 2020
N/A· v4
6.8 MEDIUM· v3
4.3 MEDIUM· v2
An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK devices through 3.3. Broadcasting forged beacon frames forces a device to...Show more
An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK devices through 3.3. Broadcasting forged beacon frames forces a device to change its authentication mode to OPEN, effectively disabling its 802.11 encryption.Show less
1Espressif
4Esp32 D0wd Firmware
Esp32 D2wd FirmwareEsp32 Pico D4 Firmware+1 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical access to the device)...Show more
An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical access to the device) to read the contents of read-protected eFuses, such as flash encryption and secure boot keys, by injecting a glitch into the power supply of the chip shortly after reset.Show less
1Espressif
1Esp Idf
Jun 17, 2026
Oct 7, 2019
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
An issue was discovered in Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.6, 3.2.x through 3.2.3, and 3.3.x through 3.3.1. An attacker who uses fault injection to physically disrupt the ESP32 CPU can bypas...Show more
An issue was discovered in Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.6, 3.2.x through 3.2.3, and 3.3.x through 3.3.1. An attacker who uses fault injection to physically disrupt the ESP32 CPU can bypass the Secure Boot digest verification at startup, and boot unverified code from flash. The fault injection attack does not disable the Flash Encryption feature, so if the ESP32 is configured with the recommended combination of Secure Boot and Flash Encryption, then the impact is minimized. If the ESP32 is configured without Flash Encryption then successful fault injection allows arbitrary code execution. To protect devices with Flash Encryption and Secure Boot enabled against this attack, a firmware change must be made to permanently enable Flash Encryption in the field if it is not already permanently enabled.Show less