PT-2023-25332 · Espressif · Espressif Esp32
Published
2023-07-17
·
Updated
2023-07-28
·
CVE-2023-35818
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Espressif ESP32 version 3.0 (ESP32 rev300 ROM)
Description
An issue was discovered that allows an attacker to influence the PC value at the CPU context level through an EMFI attack on ECO3, regardless of Secure Boot and Flash Encryption status. This capability can be used to exploit another behavior in the chip, gaining unauthorized access to the ROM download mode. Access to ROM download mode may be further exploited to read the encrypted flash content in cleartext format or execute stub code.
Recommendations
For Espressif ESP32 version 3.0 (ESP32 rev300 ROM), at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Espressif Esp32