LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-45328

espressif · esp-idf

Published
CVSS9.3
Severitycritical
WeaknessCWE-20
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c that bridge calls from the user application (i.e. the REE) to TEE-protected hardware peripherals (AES, SHA, ECC, HMAC, SPI, MMU, WDT) and to the security feature like attestation, OTA updates, secure storage. This issue has been patched in versions 5.5.5 and 6.0.1.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-45328

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-45328.