Input validation error in ESP8266_NONOS_SDK - CVE-2019-12588

 

Input validation error in ESP8266_NONOS_SDK - CVE-2019-12588

Published: September 9, 2019


Vulnerability identifier: #VU20935
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2019-12588
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vendor: Espressif Systems
Affected software:
ESP8266_NONOS_SDK

Detailed vulnerability description

The vulnerability allows a local attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper validation of the RSN AuthKey suite list count in beacon frames, probe responses, and association responses by the client 802.11 mac implementation. A local attacker in radio range can send a specially crafted message and crash the application.


How to mitigate CVE-2019-12588

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Sources