espressif.esp-idf is vulnerable to Out-of-bounds Read
75
High Risk
Affected versions of this package include a vulnerable release of Apache NimBLE, which suffers from an out-of-bounds read due to improper validation of the HCI Number Of Completed Packets field. This flaw may lead to invalid memory access when parsing HCI events, potentially reading from unintended areas of HCI transport memory. Exploitation requires a broken or malicious Bluetooth controller, which limits the practical impact, and the severity is therefore considered low.
You are affected if you are using a version that falls within the vulnerable range.
espressif.esp-idf is vulnerable to Out-of-bounds Read in versions 0.2.1 - 5.3.2.
Upgrade the espressif.esp-idf library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant