← Πίσω στην αναζήτηση CVE

CVE-2026-42855

arduino-esp32

Περιγραφή

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer Digest authentication implementation in arduino-esp32 computes the authentication hash using the URI field from the client-s Authorization header, without verifying that it matches the actual requested URI. This allows an attacker who possesses any valid digest response (computed for URI-A) to authenticate requests to a completely different protected URI (URI-B), bypassing per-resource access control. This vulnerability is fixed in 3.3.8.

CVSS 7.5EPSS 0.35100000000000003%Κίνδυνος 0.77
Προβολή πηγής
Δημοσίευση
2026-05-12 22:16:35
Επηρεαζόμενες εκδόσεις
<3.3.8
Τύπος
Υλικολογισμικό
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N