CVE-2024-33454: Buffer Overflow
Published May 14, 2024
·Updated
Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component.
Affected Software
2 affected components
Espressif ESP-IDF
Espressif ESP-IDF=5.1
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·03:37 PM
Data Sourced
via NVD·03:37 PM
DescriptionSeverityWeaknessAffected Software
Aug 2, 2024
Data Sourced
via MITRE·02:35 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-33454?
CVE-2024-33454 has a severity rating that indicates a high risk due to the potential for remote code execution.
2
How do I fix CVE-2024-33454?
To fix CVE-2024-33454, update to the latest version of Espressif ESP-IDF that addresses the buffer overflow vulnerability.
3
What types of attacks can exploit CVE-2024-33454?
CVE-2024-33454 can be exploited through crafted scripts targeting the Bluetooth stack component, allowing arbitrary code execution.
4
Which versions of Espressif ESP-IDF are affected by CVE-2024-33454?
Espressif ESP-IDF version 5.1 is confirmed to be affected by CVE-2024-33454.
5
Who is impacted by CVE-2024-33454?
Users and developers utilizing Espressif ESP-IDF v.5.1 for Bluetooth applications are impacted by CVE-2024-33454.