PT-2025-47184 · Espressif · Esp32 +1

Published

2025-11-17

·

Updated

2025-11-17

·

CVE-2025-64342

CVSS v4.0
6.9
VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ESF-IDF versions prior to 5.1.7 ESF-IDF versions prior to 5.2.6 ESF-IDF versions prior to 5.3.5 ESF-IDF versions prior to 5.4.3 ESF-IDF versions prior to 5.5.2
Description ESF-IDF, the Espressif Internet of Things (IOT) Development Framework, is affected by an issue where the ESP32, while in advertising mode, may cease advertising unexpectedly upon receiving a connection request with an invalid Access Address (AA) of 0x00000000 or 0xFFFFFFFF. This can lead to the controller incorrectly reporting a connection event to the host, potentially causing the application layer to falsely believe a successful connection has been established.
Recommendations Update to ESF-IDF version 5.1.7 or later. Update to ESF-IDF version 5.2.6 or later. Update to ESF-IDF version 5.3.5 or later. Update to ESF-IDF version 5.4.3 or later. Update to ESF-IDF version 5.5.2 or later.

Fix

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2025-64342
GHSA-8MG7-9QPG-P92V

Affected Products

Esf-Idf
Esp32