Esp Idf
Vendor:
First CVE: May 13, 2019 · Active for 7 years
31
Total CVEs
More Total CVEs than 97% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Esp Idf over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 13, 2019
7 years ago
Most Recent CVE
Jun 10, 2026
48 days ago
CVE Severity & Scoring
Esp Idf31 CVEs
48%
45%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (6.5%)
Network9 (29.0%)
Unknown0 (0.0%)
Physical3 (9.7%)
Adjacent Network17 (54.8%)
Attack Complexity
Low28 (90.3%)
High3 (9.7%)
Unknown0 (0.0%)
User Interaction
None27 (87.1%)
Unknown0 (0.0%)
Required4 (12.9%)
Privileges Required
Low4 (12.9%)
High1 (3.2%)
None26 (83.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45328HIGH ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c a | Jun 10, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-45541HIGH ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprot | Jun 10, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-45542HIGH ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SR | Jun 10, 2026 | 7.1 | 29 | NO | NO |
CVE-2025-66409CRITICAL ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, when AVRCP is enabled on ESP32, receiving a malformed VE | Dec 2, 2025 | 9.1 | 28 | NO | NO |
CVE-2025-55297HIGH ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential hand | Aug 21, 2025 | 8.8 | 28 | NO | NO |
CVE-2022-24893HIGH ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a memory corruption vulnerability can be triggered during prov | Jun 25, 2022 | 8.8 | 28 | NO | NO |
CVE-2026-45160MEDIUM ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read flaw exists in the DHCP server opt | Jun 10, 2026 | 6.5 | 27 | NO | NO |
CVE-2021-28139HIGH The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly restrict the Feature Page upon reception of an LMP Feature Response Extended packet, all | Sep 7, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-12587HIGH The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 allows the installation of a zero Pairwise Master Key (PMK) after the | Sep 4, 2019 | 8.1 | 27 | NO | NO |
CVE-2026-45329MEDIUM ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure_ | Jun 10, 2026 | 6.5 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (31 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (31 CVEs).
Media Mentions
Signals from CVEs in this product scope (31 CVEs).
Top CNAs Publishing CVEs For Esp Idf
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.0.1 | 1 | 6.5 | 0.3% | 0 | 0 |
| 6.0 | 5 | 6.9 | 0.3% | 0 | 0 |
| 5.5.4 | 5 | 7.3 | 0.3% | 0 | 0 |
| 5.5.3 | 1 | 4.6 | 0.2% | 0 | 0 |
| 5.5.2 | 3 | 6.9 | 0.2% | 0 | 0 |
| 5.5.1 | 2 | 8.1 | 0.4% | 0 | 0 |
| 5.4.4 | 4 | 6.4 | 0.3% | 0 | 0 |
| 5.4.3 | 5 | 7.4 | 0.3% | 0 | 0 |
| 5.4.1 | 1 | 9.8 | 0.7% | 0 | 0 |
| 5.3.5 | 4 | 6.4 | 0.3% | 0 | 0 |
| 5.3.4 | 5 | 7.4 | 0.3% | 0 | 0 |
| 5.3.3 | 1 | 9.8 | 0.7% | 0 | 0 |
| 5.3 | 2 | 8.2 | 0.5% | 0 | 0 |
| 5.2.7 | 1 | 6.5 | 0.3% | 0 | 0 |
| 5.2.6 | 8 | 7.0 | 0.3% | 0 | 0 |
| 5.2.5 | 1 | 9.8 | 0.7% | 0 | 0 |
| 5.2 | 1 | 5.7 | 0.2% | 0 | 0 |
| 5.1.6 | 6 | 7.8 | 0.3% | 0 | 0 |
| 5.1.3 | 1 | 5.7 | 0.2% | 0 | 0 |
| 5.1 | 2 | 7.3 | 1.1% | 0 | 0 |