SB2019091004 - Denial of Service in Espressif ESP8266_NONOS_SDK
Published: September 10, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Input validation error (CVE-ID: CVE-2019-12588)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper validation of the RSN AuthKey suite list count in beacon frames, probe responses, and association responses by the client 802.11 mac implementation. A local attacker in radio range can send a specially crafted message and crash the application.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.