PT-2023-25332 · Espressif · Espressif Esp32

Published

2023-07-17

·

Updated

2023-07-28

·

CVE-2023-35818

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Espressif ESP32 version 3.0 (ESP32 rev300 ROM)
Description An issue was discovered that allows an attacker to influence the PC value at the CPU context level through an EMFI attack on ECO3, regardless of Secure Boot and Flash Encryption status. This capability can be used to exploit another behavior in the chip, gaining unauthorized access to the ROM download mode. Access to ROM download mode may be further exploited to read the encrypted flash content in cleartext format or execute stub code.
Recommendations For Espressif ESP32 version 3.0 (ESP32 rev300 ROM), at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-35818

Affected Products

Espressif Esp32