CVE Feed

    Dashboard / CVE / CVE-2019-17391

    CVE-2019-17391

    An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical access to the device) to read the contents of read-protected eFuses, such as flash encryption and secure boot keys, by injecting a glitch into the power supply of the chip shortly after reset.

    Published:Nov 14, 2019
    Last Modified:Nov 21, 2024
    EPS:Nov 14, 2019
    EPSS Score:0.0042
    CVSS Score:4.6

    Affected Products

    Vendor
    Espressif
    Product
    Esp32-d0wd
    Vendor
    Espressif
    Product
    Esp32-d0wd Firmware
    Vendor
    Espressif
    Product
    Esp32-d2wd
    Vendor
    Espressif
    Product
    Esp32-d2wd Firmware
    Vendor
    Espressif
    Product
    Esp32-pico-d4
    Vendor
    Espressif
    Product
    Esp32-pico-d4 Firmware
    Vendor
    Espressif
    Product
    Esp32-s0wd
    Vendor
    Espressif
    Product
    Esp32-s0wd Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High