PT-2026-48350 · Espressif Systems · Esp-Idf
CVE-2026-45328
·
Published
2026-06-10
·
Updated
2026-06-10
CVSS v3.1
9.3
Critical
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ESP-IDF versions 5.5.4 through 5.5.4
ESP-IDF version 6.0
Description
The
esp tee component exposes secure-service wrappers in esp secure services.c and esp secure services iram.c that bridge calls from the user application (the Rich Execution Environment or REE) to TEE-protected hardware peripherals, including AES, SHA, ECC, HMAC, SPI, MMU, and WDT, as well as security features such as attestation, OTA updates, and secure storage. This configuration allows for an authentication bypass.Recommendations
Update version 5.5.4 to 5.5.5.
Update version 6.0 to 6.0.1.
Exploit
Fix
Memory Corruption
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Esp-Idf