PT-2024-4251 · Espressif · Esp-Idf

Elttam

+1

·

Published

2024-03-25

·

Updated

2025-12-05

·

CVE-2024-28183

CVSS v3.1

6.1

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ESP-IDF versions prior to 4.4.7 ESP-IDF versions prior to 5.2.1
Description A Time-of-Check to Time-of-Use (TOCTOU) vulnerability was discovered in the implementation of the ESP-IDF bootloader, which could allow an attacker with physical access to flash of the device to bypass anti-rollback protection. This attack can allow booting past a partition with a lower security version, even in the presence of a flash encryption scheme. The vulnerability requires carefully modifying the flash contents after the anti-rollback checks have been performed by the bootloader.
Recommendations For ESP-IDF versions prior to 4.4.7, update to version 4.4.7 or later. For ESP-IDF versions prior to 5.2.1, update to version 5.2.1 or later.

Exploit

Fix

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

BDU:2024-04738
CVE-2024-28183
GHSA-22X6-3756-PFP8

Affected Products

Esp-Idf