CVE-2020-13595: Medium severity espressif esp-idf vulnerability
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a reachable assertion on the host stack when receiving a packet with an MIC failure. An attacker within radio range can silently trigger the assertion (which disables the target's BLE stack) by sending a crafted sequence of BLE packets.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-13595?
CVE-2020-13595 is a vulnerability in the Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2, which can be exploited by an attacker within radio range.
How does CVE-2020-13595 impact Espressif ESP-IDF?
CVE-2020-13595 can trigger a reachable assertion on the host stack of Espressif ESP-IDF, leading to a denial of service (DoS) condition.
What is the severity of CVE-2020-13595?
CVE-2020-13595 has a severity rating of 6.5, which is considered medium.
How can an attacker exploit CVE-2020-13595?
An attacker within radio range can exploit CVE-2020-13595 by triggering a packet with a Message Integrity Check (MIC) failure, which causes the BLE controller to return the wrong number of completed BLE packets and leads to a DoS condition.
Is Espressif esp32 affected by CVE-2020-13595?
No, Espressif esp32 is not affected by CVE-2020-13595.
Where can I find more information about CVE-2020-13595?
You can find more information about CVE-2020-13595 on the CVE website and the GitHub pages of Asset Group and Espressif.