Home

Description

Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a previous connection session, creating an opportunity for attackers to execute security bypass attacks.

PUBLISHED Reserved 2024-11-20 | Published 2025-03-13 | Updated 2025-03-19 | Assigner mitre

References

github.com/espressif/esp-idf

github.com/.../BLE_TEST/blob/main/result/PoC/Esp/sk_reuse.md

cve.org (CVE-2024-53406)

nvd.nist.gov (CVE-2024-53406)

Download JSON