CVE-2023-46894

Description

In certain circumstances, esptool was found to use a weak cryptographic algorithm. An attacker can exploit weak or outdated encryption algorithms to expose confidential information.

Statement

Esptool has migrated to stronger encryption algorithms, but continues to support AES ECB when necessary to maintain compatibility with older chip revisions.

Understanding the Weakness (CWE)

Access Control,Confidentiality

Technical Impact: Bypass Protection Mechanism; Read Application Data

An attacker may be able to decrypt the data using brute force attacks.

Frequently Asked Questions

Want to get errata notifications? Sign up here.