PT-2026-48350 · Espressif Systems · Esp-Idf

CVE-2026-45328

·

Published

2026-06-10

·

Updated

2026-06-10

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ESP-IDF versions 5.5.4 through 5.5.4 ESP-IDF version 6.0
Description The esp tee component exposes secure-service wrappers in esp secure services.c and esp secure services iram.c that bridge calls from the user application (the Rich Execution Environment or REE) to TEE-protected hardware peripherals, including AES, SHA, ECC, HMAC, SPI, MMU, and WDT, as well as security features such as attestation, OTA updates, and secure storage. This configuration allows for an authentication bypass.
Recommendations Update version 5.5.4 to 5.5.5. Update version 6.0 to 6.0.1.

Exploit

Fix

Memory Corruption

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45328
GHSA-MMGP-73P4-92XP

Affected Products

Esp-Idf