The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range to trigger memory corruption (and consequently a crash) in ESP32 via a replayed (duplicated) LMP packet.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-09-07T05:52:46

Updated: 2024-08-03T21:33:17.448Z

Reserved: 2021-03-11T00:00:00

Link: CVE-2021-28136

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-09-07T06:15:07.330

Modified: 2021-09-09T23:32:23.887

Link: CVE-2021-28136

cve-icon Redhat

No data.