Vulnerability Description
An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical access to the device) to read the contents of read-protected eFuses, such as flash encryption and secure boot keys, by injecting a glitch into the power supply of the chip shortly after reset.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Espressif | Esp32-D0Wd Firmware | - |
| Espressif | Esp32-D0Wd | - |
| Espressif | Esp32-D2Wd Firmware | - |
| Espressif | Esp32-D2Wd | - |
| Espressif | Esp32-S0Wd Firmware | - |
| Espressif | Esp32-S0Wd | - |
| Espressif | Esp32-Pico-D4 Firmware | - |
| Espressif | Esp32-Pico-D4 | - |
Related Weaknesses (CWE)
References
- https://www.espressif.com/en/news/Security_Advisory_Concerning_Fault_Injection_aVendor Advisory
- https://www.espressif.com/en/news/Security_Advisory_Concerning_Fault_Injection_aVendor Advisory
FAQ
What is CVE-2019-17391?
CVE-2019-17391 is a vulnerability with a CVSS score of 4.6 (MEDIUM). An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical a...
How severe is CVE-2019-17391?
CVE-2019-17391 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-17391?
Check the references section above for vendor advisories and patch information. Affected products include: Espressif Esp32-D0Wd Firmware, Espressif Esp32-D0Wd, Espressif Esp32-D2Wd Firmware, Espressif Esp32-D2Wd, Espressif Esp32-S0Wd Firmware.