Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ESP-NOW OOB Vulnerability In Group Type Message
Vulnerability Description
ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An Out-of-Bound (OOB) vulnerability was discovered in the implementation of the ESP-NOW group type message because there is no check for the addrs_num field of the group type message. This can result in memory corruption related attacks. Normally there are two fields in the group information that need to be checked, i.e., the addrs_num field and the addrs_list fileld. Since we only checked the addrs_list field, an attacker can send a group type message with an invalid addrs_num field, which will cause the message handled by the firmware to be much larger than the current buffer, thus causing a memory corruption issue that goes beyond the payload length.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Vulnerability Type
跨界内存读
Vulnerability Title
ESP-NOW 缓冲区错误漏洞
Vulnerability Description
ESP-NOW是Espressif Systems开源的一个 Wi-Fi 通信协议。 ESP-NOW 2.5.1及之前版本存在缓冲区错误漏洞,该漏洞源于实现ESP-NOW组类型消息时未检查addrs_num字段,这可能导致内存损坏相关攻击。
CVSS Information
N/A
Vulnerability Type
N/A