The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 processes EAP Success messages before any EAP method completion or failure, which allows attackers in radio range to cause a denial of service (crash) via a crafted message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Arduino-esp32 | Espressif | * | 1.0.2 (including) |
Arduino-esp32 | Espressif | 1.0.3 (including) | 1.0.3 (including) |
Arduino-esp32 | Espressif | 1.0.3-rc1 (including) | 1.0.3-rc1 (including) |
Arduino-esp32 | Espressif | 1.0.3-rc2 (including) | 1.0.3-rc2 (including) |
Esp-idf | Espressif | 2.0.0 (including) | 4.0.0 (including) |