CVE-2019-17391 Details
Description
An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical access to the device) to read the contents of read-protected eFuses, such as flash encryption and secure boot keys, by injecting a glitch into the power supply of the chip shortly after reset.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-755 | Improper Handling of Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| espressif esp32-d0wd firmware | All versions |
CPE
Remediation
| |
| espressif esp32-d0wd | All versions |
CPE
Remediation
| |
| espressif esp32-d2wd firmware | All versions |
CPE
Remediation
| |
| espressif esp32-d2wd | All versions |
CPE
Remediation
| |
| espressif esp32-s0wd firmware | All versions |
CPE
Remediation
| |
| espressif esp32-s0wd | All versions |
CPE
Remediation
| |
| espressif esp32-pico-d4 firmware | All versions |
CPE
Remediation
| |
| espressif esp32-pico-d4 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 24, 2020 | CWE Remap | [email protected] |
| Nov 21, 2019 | Initial Analysis | [email protected] |