CVE-2020-12638: Medium severity espressif esp-idf vulnerability
An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266NONOSSDK devices through 3.0.3, and ESP8266RTOSSDK devices through 3.3. Broadcasting forged beacon frames forces a device to change its authentication mode to OPEN, effectively disabling its 802.11 encryption.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-12638?
CVE-2020-12638 is an encryption-bypass vulnerability that affects Espressif ESP-IDF devices through version 4.2, ESP8266_NONOS_SDK devices through version 3.0.3, and ESP8266_RTOS_SDK devices through version 3.3.
How does CVE-2020-12638 affect Espressif ESP-IDF devices?
CVE-2020-12638 allows an attacker to broadcast forged beacon frames, forcing the device to change its authentication mode to OPEN and effectively disabling its 802.11 encryption.
Which software versions are affected by CVE-2020-12638?
Espressif ESP-IDF devices up to version 4.2, ESP8266_NONOS_SDK devices up to version 3.0.3, and ESP8266_RTOS_SDK devices up to version 3.3 are affected by CVE-2020-12638.
What is the severity of CVE-2020-12638?
CVE-2020-12638 has a severity rating of 6.8, which is considered medium.
How can I fix CVE-2020-12638?
To fix CVE-2020-12638, it is recommended to update to the latest version of the affected software as provided by Espressif.