CVE-2024-53845: AES/CBC Constant IV Vulnerability in ESPTouch v2

Published Dec 11, 2024
·
Updated

ESPTouch is a connection protocol for internet of things devices. In the ESPTouchV2 protocol, while there is an option to use a custom AES key, there is no option to set the IV (Initialization Vector) prior to versions 5.3.2, 5.2.4, 5.1.6, and 5.0.8. The IV is set to zero and remains constant throughout the product's lifetime. In AES/CBC mode, if the IV is not properly initialized, the encrypted output becomes deterministic, leading to potential data leakage. To address the aforementioned issues, the application generates a random IV when activating the AES key starting in versions 5.3.2, 5.2.4, 5.1.6, and 5.0.8. This IV is then transmitted along with the provision data to the provision device. The provision device has also been equipped with a parser for the AES IV. The upgrade is applicable for all applications and users of ESPTouch v2 component from ESP-IDF. As it is implemented in the ESP Wi-Fi stack, there is no workaround for the user to fix the application layer without upgrading the underlying firmware.

Affected Software

1 affected component
Espressif ESPTouch<5.0.8

Event History

Dec 11, 2024
CVE Published
via MITRE·10:35 PM
Data Sourced
via MITRE·10:35 PM
DescriptionWeakness
Dec 12, 2024
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-53845?

CVE-2024-53845 is considered a moderate severity vulnerability due to its potential impact on the security of IoT device communications.

2

How do I fix CVE-2024-53845?

To fix CVE-2024-53845, update the affected software ESPTouch to version 5.3.2 or later, where the IV initialization issue has been resolved.

3

What is the risk associated with using ESPTouch versions prior to 5.3.2 as referenced in CVE-2024-53845?

The risk involves the use of a static Initialization Vector, which could lead to vulnerabilities in encrypted communications, making it easier for attackers to decrypt sensitive data.

4

Which versions of ESPTouch are affected by CVE-2024-53845?

ESPTouch versions up to and including 5.0.8 are affected by CVE-2024-53845, where the IV is incorrectly initialized to zero.

5

Does CVE-2024-53845 affect all IoT devices using ESPTouch?

CVE-2024-53845 specifically affects ESPTouch v2 protocol implementations in Espressif devices that do not set a custom IV.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203