CVE-2024-45798 describes multiple critical Poisoned Pipeline Execution (PPE) vulnerabilities within the arduino-esp32 CI, specifically affecting the Arduino core for various ESP32 microcontrollers. These vulnerabilities, including code and environment variable injection, allow for remote code execution with high impact on confidentiality, integrity, and availability. While the issue has been addressed, users are urged to verify downloaded artifacts. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Espressif | Arduino-Esp32 | Commits prior to a7cec020df8f1a815bd8dfd2559f51a2216bcf1cCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.