CVE-2023-46894: Weak Encryption
Published Nov 9, 2023
·Updated
An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm.
Affected Software
2 affected components
pip/esptool<=4.6.2
Espressif Esptool=4.6.2
Event History
Nov 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
06:34 PM
Frequently Asked Questions
1
What is CVE-2023-46894?
CVE-2023-46894 is an issue discovered in esptool 4.6.2 that allows attackers to view sensitive information via a weak cryptographic algorithm.
2
How does CVE-2023-46894 affect me?
CVE-2023-46894 affects you if you are using esptool version 4.6.2.
3
What is the severity of CVE-2023-46894?
The severity of CVE-2023-46894 is not specified.
4
How can I fix CVE-2023-46894?
To fix CVE-2023-46894, update your esptool version to a secure version recommended by the vendor.
5
Where can I find more information about CVE-2023-46894?
You can find more information about CVE-2023-46894 at the following references: [GitHub Issue](https://github.com/espressif/esptool/issues/926), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-46894), [GitHub Advisory](https://github.com/advisories/GHSA-3f38-96qm-r3fw).