CVE-2018-18558

Source
https://cve.org/CVERecord?id=CVE-2018-18558
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-18558.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-18558
Published
2019-05-13T13:29:02.103Z
Modified
2026-07-08T17:56:20.284897Z
Severity
  • 6.4 (Medium) CVSS_V3 - CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1. Insufficient validation of input data in the 2nd stage bootloader allows a physically proximate attacker to bypass secure boot checks and execute arbitrary code, by crafting an application binary that overwrites a bootloader code segment in processsegment in components/bootloadersupport/src/espimageformat.c. The attack is effective when the flash encryption feature is not enabled, or if the attacker finds a different vulnerability that allows them to write this binary to flash memory.

References

Affected packages

Git / github.com/espressif/esp-idf

Affected ranges

Type
GIT
Repo
https://github.com/espressif/esp-idf
Events
Database specific
{
    "cpe": "cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.0"
        },
        {
            "fixed": "3.0.6"
        },
        {
            "introduced": "3.1"
        },
        {
            "last_affected": "3.1.1"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v3.*
v3.0
v3.0-rc1
v3.0.1
v3.0.1-rc
v3.0.2
v3.0.3
v3.0.3-rc
v3.0.4
v3.0.4-rc1
v3.0.5
v3.0.5-rc
v3.0.6-rc
v3.1
v3.1-beta1
v3.1-dev
v3.1-rc1
v3.1-rc2
v3.1.1
v3.1.1-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-18558.json"