6.5

CVE-2021-28136

The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range to trigger memory corruption (and consequently a crash) in ESP32 via a replayed (duplicated) LMP packet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EspressifEsp-idf Version <= 4.4
   EspressifEsp32 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.81% 0.521
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 3.3 6.5 2.9
AV:A/AC:L/Au:N/C:N/I:N/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://github.com/espressif/esp-idf
Third Party Advisory
Product
https://github.com/espressif/esp32-bt-lib
Third Party Advisory
Product
https://dl.packetstormsecurity.net/papers/general/braktooth.pdf
Third Party Advisory
Technical Description
https://www.espressif.com/en/products/socs/esp32
Vendor Advisory
Product