CVE-2019-12587: High severity espressif esp-idf vulnerability
The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266NONOSSDK 2.2.0 through 3.1.0 allows the installation of a zero Pairwise Master Key (PMK) after the completion of any EAP authentication method, which allows attackers in radio range to replay, decrypt, or spoof frames via a rogue access point.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-12587?
CVE-2019-12587 is a vulnerability in the EAP peer implementation in Espressif ESP-IDF and ESP8266_NONOS_SDK that allows the installation of a zero Pairwise Master Key (PMK).
What is the severity of CVE-2019-12587?
The severity of CVE-2019-12587 is rated as high, with a severity value of 8.1.
How does CVE-2019-12587 affect Espressif ESP-IDF?
CVE-2019-12587 affects Espressif ESP-IDF versions 2.0.0 through 4.0.0, allowing the installation of a zero PMK.
How does CVE-2019-12587 affect ESP8266_NONOS_SDK?
CVE-2019-12587 affects ESP8266_NONOS_SDK versions 2.2.0 through 3.1.0, allowing the installation of a zero PMK.
How can I fix CVE-2019-12587?
To fix CVE-2019-12587, it is recommended to update Espressif ESP-IDF to a version beyond 4.0.0 or update ESP8266_NONOS_SDK to a version beyond 3.1.0.