PT-2019-6219 · Espressif · Esp32

Published

2019-11-14

·

Updated

2025-04-18

·

CVE-2019-17391

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Espressif ESP32 mask ROM code versions 2016-06-08 0 through 2
Description The issue is related to the lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip, allowing an attacker with physical access to the device to read the contents of read-protected eFuses, such as flash encryption and secure boot keys, by injecting a glitch into the power supply of the chip shortly after reset. This is also associated with insufficient handling of exceptional states in the Secure Boot bootloader, which can allow an attacker to obtain secure boot keys.
Recommendations For Espressif ESP32 mask ROM code versions 2016-06-08 0 through 2, consider implementing physical security measures to prevent tampering with the device's power supply, as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

BDU:2022-03985
CVE-2019-17391

Affected Products

Esp32