CVE-2021-28135
07.09.2021, 06:15
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (crash) in ESP32 by flooding the target device with LMP Feature Response data.Enginsight
Vendor | Product | Version |
---|---|---|
espressif | esp-idf | 𝑥 ≤ 4.4 |
𝑥
= Vulnerable software versions
References