CVE-2021-28135
EUVD-2021-1483407.09.2021, 06:15
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (crash) in ESP32 by flooding the target device with LMP Feature Response data.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| espressif | esp-idf | 𝑥 ≤ 4.4 |
𝑥
= Vulnerable software versions
References