CVE-2023-46894
CVE-2023-46894 is a high-severity vulnerability (CVSS 7.5) affecting espressif esptool version 4.6.2, stemming from the use of a weak cryptographic algorithm (CWE-326). This flaw allows unauthenticated remote attackers to view sensitive information due to the cryptographic weakness. While no active exploitation, public exploit code, or significant community discussion has been observed, the potential for high confidentiality impact remains.
Impacted Technologies
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.6.2CPE matchmatch criteria | cpe:2.3:a:espressif:esptool:4.6.2:*:*:*:*:*:*:* |
CVSS Data
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploit Intelligence
Social Chatter
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
Media Mentions
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.