CVE-2018-18558: Input Validation
An issue was discovered in Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1. Insufficient validation of input data in the 2nd stage bootloader allows a physically proximate attacker to bypass secure boot checks and execute arbitrary code, by crafting an application binary that overwrites a bootloader code segment in processsegment in components/bootloadersupport/src/espimageformat.c. The attack is effective when the flash encryption feature is not enabled, or if the attacker finds a different vulnerability that allows them to write this binary to flash memory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-18558?
CVE-2018-18558 is a vulnerability in the 2nd stage bootloader of Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1.
How does CVE-2018-18558 affect Espressif ESP-IDF?
CVE-2018-18558 allows a physically proximate attacker to bypass secure boot checks and execute arbitrary code.
What is the severity of CVE-2018-18558?
CVE-2018-18558 has a severity rating of medium (CVSS score 6.4).
How can I fix CVE-2018-18558?
To fix CVE-2018-18558, update Espressif ESP-IDF to version 3.0.6 or 3.1.1.
Where can I find more information about CVE-2018-18558?
More information about CVE-2018-18558 can be found in the Espressif ESP-IDF releases page and the Espressif Product Security Advisory.