ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprotocol-negotiation path of the esp_http_server component. While parsing the client-supplied Sec-WebSocket-Protocol request header during the WebSocket handshake, the tokenisation result is dereferenced without a NULL check, so a malformed header value can crash the server before any application-level authentication runs. This issue has been patched in versions 5.2.7, 5.3.6, 5.4.5, 5.5.5, and 6.0.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2.6CPE matchmatch criteria | cpe:2.3:a:espressif:esp-idf:5.2.6:*:*:*:*:*:*:* | ||
5.3.5CPE matchmatch criteria | cpe:2.3:a:espressif:esp-idf:5.3.5:*:*:*:*:*:*:* | ||
5.4.4CPE matchmatch criteria | cpe:2.3:a:espressif:esp-idf:5.4.4:*:*:*:*:*:*:* | ||
5.5.4CPE matchmatch criteria | cpe:2.3:a:espressif:esp-idf:5.5.4:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:espressif:esp-idf:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.