CVE-2020-13595 Details
Description
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a reachable assertion on the host stack when receiving a packet with an MIC failure. An attacker within radio range can silently trigger the assertion (which disables the target's BLE stack) by sending a crafted sequence of BLE packets.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://asset-group.github.io/cves.html | CVE | Third Party Advisory |
| https://asset-group.github.io/disclosures/sweyntooth/ | CVE | Third Party Advisory |
| https://github.com/espressif/esp32-bt-lib | CVE | Third Party Advisory |
| https://asset-group.github.io/cves.html | [email protected] | Third Party Advisory |
| https://asset-group.github.io/disclosures/sweyntooth/ | [email protected] | Third Party Advisory |
| https://github.com/espressif/esp32-bt-lib | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-617 | Reachable Assertion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| espressif esp-idf | >= 4.0.0, <= 4.2 |
CPE
Remediation
| |
| espressif esp32 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Sep 8, 2020 | Initial Analysis | [email protected] |