CVE-2024-53845
Last modified
CVE-2024-53845 is a medium-severity vulnerability rated 6.6/10 on the CVSS scale. ESPTouch is a connection protocol for internet of things devices. In the ESPTouchV2 protocol, while there is an option to use a custom AES key, there is no option to set the IV (Initialization Vector) prior to versions 5.3.2, 5.2.4, 5.1.6, and 5.0.8. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
ESPTouch is a connection protocol for internet of things devices. In the ESPTouchV2 protocol, while there is an option to use a custom AES key, there is no option to set the IV (Initialization Vector) prior to versions 5.3.2, 5.2.4, 5.1.6, and 5.0.8. The IV is set to zero and remains constant throughout the product's lifetime. In AES/CBC mode, if the IV is not properly initialized, the encrypted output becomes deterministic, leading to potential data leakage. To address the aforementioned issues, the application generates a random IV when activating the AES key starting in versions 5.3.2, 5.2.4, 5.1.6, and 5.0.8. This IV is then transmitted along with the provision data to the provision device. The provision device has also been equipped with a parser for the AES IV. The upgrade is applicable for all applications and users of ESPTouch v2 component from ESP-IDF. As it is implemented in the ESP Wi-Fi stack, there is no workaround for the user to fix the application layer without upgrading the underlying firmware.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-53845?
How severe is CVE-2024-53845?
How do I fix CVE-2024-53845?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-5384A vulnerability classified as critical was found in SourceCo…9.8
- CVE-2024-53840there is a possible biometric bypass due to an unusual root …7.8
- CVE-2024-53841In startListeningForDeviceStateChanges, there is a possible …7.8
- CVE-2024-53842In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is …9.8
- CVE-2024-53843@dapperduckling/keycloak-connector-server is an opinionated …8.1
- CVE-2024-53844E.D.D.I (Enhanced Dialog Driven Interface) is a middleware t…6.3
- CVE-2024-53846OTP is a set of Erlang libraries, which consists of the Erla…5.5
- CVE-2024-53847The Trix rich text editor, prior to versions 2.1.9 and 1.3.3…5.1
- CVE-2024-53848check-jsonschema is a CLI and set of pre-commit hooks for js…7.1
- CVE-2024-53849editorconfig-core-c is theEditorConfig core library writte…4.8
- CVE-2024-5385A vulnerability, which was classified as problematic, has be…4.1
- CVE-2024-53850The Addressing GLPI plugin enables you to create IP reports …8.2
Are you affected by CVE-2024-53845?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
