CVE-2019-12586: Medium severity espressif arduino-esp32 vulnerability
The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266NONOSSDK 2.2.0 through 3.1.0 processes EAP Success messages before any EAP method completion or failure, which allows attackers in radio range to cause a denial of service (crash) via a crafted message.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-12586?
CVE-2019-12586 is a vulnerability in the EAP peer implementation in Espressif ESP-IDF and ESP8266_NONOS_SDK that allows attackers in radio range to cause a denial of service (crash) via a crafted message.
Which software versions are affected by CVE-2019-12586?
Espressif ESP-IDF versions 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK versions 2.2.0 through 3.1.0 are affected by CVE-2019-12586.
What is the severity of CVE-2019-12586?
The severity of CVE-2019-12586 is medium with a CVSS score of 6.5.
How can an attacker exploit CVE-2019-12586?
An attacker within radio range can exploit CVE-2019-12586 by sending a crafted message, causing the EAP peer implementation to crash.
How can I protect myself from CVE-2019-12586?
To protect yourself from CVE-2019-12586, make sure to update to the latest version of Espressif ESP-IDF and ESP8266_NONOS_SDK that includes a fix for this vulnerability.