Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-45328

36
FAUCET Score

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c that bridge calls from the user application (i.e. the REE) to TEE-protected hardware peripherals (AES, SHA, ECC, HMAC, SPI, MMU, WDT) and to the security feature like attestation, OTA updates, secure storage. This issue has been patched in versions 5.5.5 and 6.0.1.

First published: Jun 10, 2026Last modified: Jun 10, 2026

Impacted Technologies

VendorProductVersion(s)CPE
5.5.4CPE matchmatch criteria
cpe:2.3:a:espressif:esp-idf:5.5.4:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:a:espressif:esp-idf:6.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.3CRITICAL

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.5
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
2.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 12th percentile among its peer group of 16,994 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / espressif/esp-idf/commit/145ba4c42dc8283054cfde9a1c3470db7399192f
Patch
github.com / espressif/esp-idf/commit/440a5d1906502023f2a0fb0aecbdf0602d14acbf
Patch
github.com / espressif/esp-idf/commit/764626a1b7c85b943d207da08a2f8f7d7f3def4d
Patch
github.com / espressif/esp-idf/commit/7867f4a57560bf9fc4a931e37ba02b7a3e9f406b
Patch
github.com / espressif/esp-idf/commit/afd14ab113acd0ca369965404c99ac42e74d4fcd
Patch
github.com / espressif/esp-idf/commit/eebabaff2fdc273b1530fe66e55fb3bcd181dfd6
Patch
github.com / espressif/esp-idf/security/advisories/GHSA-mmgp-73p4-92xp
MitigationPatchVendor Advisory