#VU20935 Input validation error in ESP8266_NONOS_SDK - CVE-2019-12588
Published: September 9, 2019
ESP8266_NONOS_SDK
Espressif Systems
Description
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper validation of the RSN AuthKey suite list count in beacon frames, probe responses, and association responses by the client 802.11 mac implementation. A local attacker in radio range can send a specially crafted message and crash the application.