We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-53406



Description

Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a previous connection session, creating an opportunity for attackers to execute security bypass attacks.

Reserved 2024-11-20 | Published 2025-03-13 | Updated 2025-03-13 | Assigner mitre

References

github.com/espressif/esp-idf

github.com/.../BLE_TEST/blob/main/result/PoC/Esp/sk_reuse.md

cve.org (CVE-2024-53406)

nvd.nist.gov (CVE-2024-53406)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-53406

Support options

Helpdesk Chat, Email, Knowledgebase