VYPR
Medium severity6.5NVD Advisory· Published Sep 7, 2021· Updated Jun 17, 2026

CVE-2021-28136

CVE-2021-28136

Description

The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range to trigger memory corruption (and consequently a crash) in ESP32 via a replayed (duplicated) LMP packet.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Espressif/Esp Idf2 versions
    cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:*range: <=4.4
    • (no CPE)range: <=4.4
  • Espressif/ESP-IDFdescription
  • Espressif/ESP32llm-fuzzy
    Range: <=4.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.