CVE-2021-34173: High severity espressif esp32 firmware vulnerability
Published Jul 14, 2021
·Updated
An attacker can cause a Denial of Service and kernel panic in v4.2 and earlier versions of Espressif esp32 via a malformed beacon csa frame. The device requires a reboot to recover.
Affected Software
2 affected components
Espressif Esp32 Firmware<=4.2
Espressif ESP32
Event History
Jul 14, 2021
CVE Published
via MITRE·06:32 PM
Data Sourced
via MITRE·06:32 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-34173.
2
What is the severity of CVE-2021-34173?
The severity of CVE-2021-34173 is high, with a severity score of 7.5.
3
Which versions of Espressif esp32 firmware are affected by CVE-2021-34173?
Versions up to and including 4.2 of Espressif esp32 firmware are affected by CVE-2021-34173.
4
How does the vulnerability in CVE-2021-34173 manifest?
The vulnerability in CVE-2021-34173 allows an attacker to cause a Denial of Service and kernel panic on affected devices by sending a malformed beacon csa frame.
5
How can I recover from the Denial of Service and kernel panic caused by CVE-2021-34173?
To recover from the Denial of Service and kernel panic caused by CVE-2021-34173, the affected device requires a reboot.