Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-45542

29
FAUCET Score

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SRP6a) session-setup path of the protocomm component. The first-phase handler (handle_session_command0() in components/protocomm/src/security/security2.c) trusts the length of a client-supplied protobuf field for the SRP6a username and copies it into a buffer whose size is derived from a narrower destination type. The resulting truncation-versus-copy asymmetry corrupts the heap when an oversized value is supplied. This issue has been patched in versions 5.2.7, 5.3.6, 5.4.5, 5.5.5, and 6.0.1.

First published: Jun 10, 2026Last modified: Jun 10, 2026

Impacted Technologies

VendorProductVersion(s)CPE
5.2.6CPE matchmatch criteria
cpe:2.3:a:espressif:esp-idf:5.2.6:*:*:*:*:*:*:*
5.3.5CPE matchmatch criteria
cpe:2.3:a:espressif:esp-idf:5.3.5:*:*:*:*:*:*:*
5.4.4CPE matchmatch criteria
cpe:2.3:a:espressif:esp-idf:5.4.4:*:*:*:*:*:*:*
5.5.4CPE matchmatch criteria
cpe:2.3:a:espressif:esp-idf:5.5.4:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:a:espressif:esp-idf:6.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.33%
Probability of exploitation in next 30 days
EPSS Percentile
24.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 21st percentile among its peer group of 1,859 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / espressif/esp-idf/commit/0ea58d79845ad674d0358d5de246015a68c4cb4f
Patch
github.com / espressif/esp-idf/commit/56c3e385611e63162d0f2f8504ac4ae2ccfccef0
Patch
github.com / espressif/esp-idf/commit/71eb2dbe6aaef830719ecac8edf409e2992b64b2
Patch
github.com / espressif/esp-idf/commit/9b4cacf9cbc69379972de6a2247fcf5af9240961
Patch
github.com / espressif/esp-idf/commit/a2f4554f10ba075c98cbc67464db096ba32497cf
Patch
github.com / espressif/esp-idf/commit/f5d24a7e919bc5f447091479656b86da6762a103
Patch
github.com / espressif/esp-idf/security/advisories/GHSA-9r76-858f-v6jh
MitigationPatchVendor Advisory