CVE-2019-17391
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical access to the device) to read the contents of read-protected eFuses, such as flash encryption and secure boot keys, by injecting a glitch into the power supply of the chip shortly after reset.
Se descubrió un problema en el código ROM de la máscara de Espressif ESP32 08-06-2016 desde 0 hasta 2. La falta de mitigaciones contra fallos en el cargador de arranque de la primera etapa del chip ESP32 permite a un atacante (con acceso físico al dispositivo) leer el contenido de eFuses protegidos contra lectura, tales como el cifrado flash y las claves de arranque seguras, al inyectar un fallo en la fuente de alimentación del chip poco después del reinicio.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-10-09 CVE Reserved
- 2019-11-14 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-755: Improper Handling of Exceptional Conditions
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Espressif Search vendor "Espressif" | Esp32-d0wd Firmware Search vendor "Espressif" for product "Esp32-d0wd Firmware" | - | - |
Affected
| in | Espressif Search vendor "Espressif" | Esp32-d0wd Search vendor "Espressif" for product "Esp32-d0wd" | - | - |
Safe
|
Espressif Search vendor "Espressif" | Esp32-d2wd Firmware Search vendor "Espressif" for product "Esp32-d2wd Firmware" | - | - |
Affected
| in | Espressif Search vendor "Espressif" | Esp32-d2wd Search vendor "Espressif" for product "Esp32-d2wd" | - | - |
Safe
|
Espressif Search vendor "Espressif" | Esp32-s0wd Firmware Search vendor "Espressif" for product "Esp32-s0wd Firmware" | - | - |
Affected
| in | Espressif Search vendor "Espressif" | Esp32-s0wd Search vendor "Espressif" for product "Esp32-s0wd" | - | - |
Safe
|
Espressif Search vendor "Espressif" | Esp32-pico-d4 Firmware Search vendor "Espressif" for product "Esp32-pico-d4 Firmware" | - | - |
Affected
| in | Espressif Search vendor "Espressif" | Esp32-pico-d4 Search vendor "Espressif" for product "Esp32-pico-d4" | - | - |
Safe
|