CVE-2019-17391

4.6
MEDIUMCVSS v3.1 Base Score
0.24%
LOW RiskEPSS (13th percentile)

An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical access to the device) to read the contents of read-protected eFuses, such as flash encryption and secure boot keys, by injecting a glitch into the power supply of the chip shortly after reset.

Published: 11/14/2019
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

4.6MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v2 Score

2.1

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS Score (Exploitation Probability)

0.24%LOW Exploitation Risk
13th percentile

This vulnerability has a 0.24% probability of being exploited in the next 30 days, ranking higher than 13% of all scored CVEs.

CWE Classification

Advertisement