PT-2019-12875 · Espressif · Esp8266 Nonos Sdk+1

Published

2019-09-04

·

Updated

2025-12-12

·

CVE-2019-12586

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Espressif ESP-IDF versions 2.0.0 through 4.0.0 Espressif ESP8266 NONOS SDK versions 2.2.0 through 3.1.0
Description The issue concerns the EAP peer implementation, which processes EAP Success messages prematurely. This allows attackers within radio range to craft a message that can cause a denial of service, leading to a crash.
Recommendations For Espressif ESP-IDF versions 2.0.0 through 4.0.0, update to a version outside of this range to resolve the issue. For Espressif ESP8266 NONOS SDK versions 2.2.0 through 3.1.0, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to EAP Success messages until a patch is available.

Exploit

Fix

Related Identifiers

CVE-2019-12586

Affected Products

Esp-Idf
Esp8266 Nonos Sdk