CVE-2025-64342
中文标题:
(暂无数据)
英文标题:
ESF-IDF's ESP32 Bluetooth Controller Has an Invalid Access Address Vulnerability
漏洞描述
中文描述:
(暂无数据)
英文描述:
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. When the ESP32 is in advertising mode, if it receives a connection request containing an invalid Access Address (AA) of 0x00000000 or 0xFFFFFFFF, advertising may stop unexpectedly. In this case, the controller may incorrectly report a connection event to the host, which can cause the application layer to assume that the device has successfully established a connection. This issue has been fixed in versions 5.5.2, 5.4.3, 5.3.5, 5.2.6, and 5.1.7. At time of publication versions 5.5.2, 5.3.5, and 5.1.7 have not been released but are fixed respectively in commits 3b95b50, e3d7042, and 75967b5.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| espressif | esp-idf | >= 5.5-beta1, < 5.5.2 | - | - |
cpe:2.3:a:espressif:esp-idf:>=_5.5-beta1,_<_5.5.2:*:*:*:*:*:*:*
|
| espressif | esp-idf | >= 5.4-beta1, < 5.4.3 | - | - |
cpe:2.3:a:espressif:esp-idf:>=_5.4-beta1,_<_5.4.3:*:*:*:*:*:*:*
|
| espressif | esp-idf | >= 5.3-beta1, < 5.3.5 | - | - |
cpe:2.3:a:espressif:esp-idf:>=_5.3-beta1,_<_5.3.5:*:*:*:*:*:*:*
|
| espressif | esp-idf | >= 5.2-beta1, < 5.2.6 | - | - |
cpe:2.3:a:espressif:esp-idf:>=_5.2-beta1,_<_5.2.6:*:*:*:*:*:*:*
|
| espressif | esp-idf | < 5.1.7 | - | - |
cpe:2.3:a:espressif:esp-idf:<_5.1.7:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
4.0 (cna)
MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-64342 |
2025-11-19 04:05:47 | 2026-01-12 02:12:18 |
| NVD | nvd_CVE-2025-64342 |
2025-11-19 04:07:44 | 2026-01-12 02:28:00 |
版本与语言
安全公告
变更历史
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']