CVE-2020-13594: Input Validation
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does not properly restrict the channel map field of the connection request packet on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-13594?
CVE-2020-13594 is a vulnerability in the Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier, which allows attackers in radio range to cause a denial of service (crash) via a crafted packet.
How does CVE-2020-13594 affect Espressif ESP-IDF?
CVE-2020-13594 affects Espressif ESP-IDF versions up to and including 4.2.
How does CVE-2020-13594 impact ESP32 devices?
CVE-2020-13594 impacts ESP32 devices when using Espressif ESP-IDF versions up to and including 4.2.
What is the severity of CVE-2020-13594?
The severity of CVE-2020-13594 is medium, with a CVSS score of 6.5.
How can I fix CVE-2020-13594?
To fix CVE-2020-13594, it is recommended to update to a version of Espressif ESP-IDF that is later than 4.2, once the fix is available.