216.73.217.22

CVE-2026-45328

· Published 10/06/2026 02:16 · Modified 11/06/2026 18:15

Labels: CVE-2026-45328 2026-06-10CVE-2026-45328CWE-20CWE-787[email protected]

Essential information

Published
10/06/2026 02:16
Modified
11/06/2026 18:15
Author
Creator
CVSS
9.3 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c that bridge calls from the user application (i.e. the REE) to TEE-protected hardware peripherals (AES, SHA, ECC, HMAC, SPI, MMU, WDT) and to the security feature like attestation, OTA updates, secure storage. This issue has been patched in versions 5.5.5 and 6.0.1.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
espressif / esp-idf cpe:2.3:a:espressif:esp-idf:5.5.4:*:*:*:*:*:*:*
espressif / esp-idf cpe:2.3:a:espressif:esp-idf:6.0:*:*:*:*:*:*:*

References