CVE-2023-46894
Description
In certain circumstances, esptool was found to use a weak cryptographic algorithm. An attacker can exploit weak or outdated encryption algorithms to expose confidential information.
Statement
Esptool has migrated to stronger encryption algorithms, but continues to support AES ECB when necessary to maintain compatibility with older chip revisions.
Understanding the Weakness (CWE)
Access Control,Confidentiality
Technical Impact: Bypass Protection Mechanism; Read Application Data
An attacker may be able to decrypt the data using brute force attacks.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.