CVE-2019-15894
- EPSS 0.46%
- Veröffentlicht 07.10.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:40
An issue was discovered in Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.6, 3.2.x through 3.2.3, and 3.3.x through 3.3.1. An attacker who uses fault injection to physically disrupt the ESP32 CPU can bypass the Secure Boot digest verif...
CVE-2019-12586
- EPSS 1.35%
- Veröffentlicht 04.09.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 04:23:08
The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 processes EAP Success messages before any EAP method completion or failure, which allows attackers in radio range to cause a denial of serv...
CVE-2019-12587
- EPSS 0.8%
- Veröffentlicht 04.09.2019 12:15:11
- Zuletzt bearbeitet 21.11.2024 04:23:08
The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 allows the installation of a zero Pairwise Master Key (PMK) after the completion of any EAP authentication method, which allows attackers i...
CVE-2018-18558
- EPSS 0.39%
- Veröffentlicht 13.05.2019 13:29:02
- Zuletzt bearbeitet 21.11.2024 03:56:09
An issue was discovered in Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1. Insufficient validation of input data in the 2nd stage bootloader allows a physically proximate attacker to bypass secure boot checks and execute arbitrary ...