Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-13595

Опубликовано: 31 авг. 2020
Источник: nvd
CVSS3: 6.5
CVSS2: 3.3
EPSS Низкий

Описание

The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a reachable assertion on the host stack when receiving a packet with an MIC failure. An attacker within radio range can silently trigger the assertion (which disables the target's BLE stack) by sending a crafted sequence of BLE packets.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.2 (включая)
cpe:2.3:h:espressif:esp32:-:*:*:*:*:*:*:*

EPSS

Процентиль: 47%
0.00237
Низкий

6.5 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-617

Связанные уязвимости

github
больше 3 лет назад

The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a reachable assertion on the host stack when receiving a packet with an MIC failure. An attacker within radio range can silently trigger the assertion (which disables the target's BLE stack) by sending a crafted sequence of BLE packets.

EPSS

Процентиль: 47%
0.00237
Низкий

6.5 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-617