CVE-2020-16146: Buffer Overflow
Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x through 4.0.1 has a Buffer Overflow in BluFi provisioning in btcblufirecvhandler function in blufiprf.c. An attacker can send a crafted BluFi protocol Write Attribute command to characteristic 0xFF01. With manipulated packet fields, there is a buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-16146?
CVE-2020-16146 is a vulnerability in Espressif ESP-IDF, which can lead to a buffer overflow in BluFi provisioning.
How does CVE-2020-16146 impact Espressif ESP-IDF?
CVE-2020-16146 can allow an attacker to send a crafted BluFi protocol Write Attribute command to cause a buffer overflow in the function btc_blufi_recv_handler in blufi_prf.c.
What is the severity of CVE-2020-16146?
CVE-2020-16146 has a severity score of 7.5, which is considered high.
Which versions of Espressif ESP-IDF are affected by CVE-2020-16146?
Espressif ESP-IDF versions 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x through 4.0.1 are affected by CVE-2020-16146.
Is there a fix available for CVE-2020-16146?
To fix CVE-2020-16146, it is recommended to upgrade to a patched version of Espressif ESP-IDF.