CVE-2021-28136
Estado: ModificadaMedia (6.5)—
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range to trigger memory corruption (and consequently a crash) in ESP32 via a replayed (duplicated) LMP packet.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.84%
- Percentil entre todas las CVEs puntuadas: 56
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-787
Referencias
- https://dl.packetstormsecurity.net/papers/general/braktooth.pdf
- https://github.com/espressif/esp-idf
- https://github.com/espressif/esp32-bt-lib
- https://www.espressif.com/en/products/socs/esp32
- https://dl.packetstormsecurity.net/papers/general/braktooth.pdf
- https://github.com/espressif/esp-idf
- https://github.com/espressif/esp32-bt-lib
- https://www.espressif.com/en/products/socs/esp32
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-28136",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.3,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.5,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2021-09-07T06:15:07.330",
"references": [
{
"url": "https://dl.packetstormsecurity.net/papers/general/braktooth.pdf",
"tags": [
"Technical Description",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/espressif/esp-idf",
"tags": [
"Product",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/espressif/esp32-bt-lib",
"tags": [
"Product",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.espressif.com/en/products/socs/esp32",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://dl.packetstormsecurity.net/papers/general/braktooth.pdf",
"tags": [
"Technical Description",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/espressif/esp-idf",
"tags": [
"Product",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/espressif/esp32-bt-lib",
"tags": [
"Product",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.espressif.com/en/products/socs/esp32",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-787"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range to trigger memory corruption (and consequently a crash) in ESP32 via a replayed (duplicated) LMP packet."
},
{
"lang": "es",
"value": "Una implementación de Bluetooth Classic en Espressif ESP-IDF versiones 4.4 y anteriores, no maneja apropiadamente la recepción de múltiples paquetes de petición de capacidad LMP IO durante el proceso de emparejamiento, permitiendo a atacantes en el rango de radio desencadenar una corrupción de la memoria (y en consecuencia un bloqueo) en el ESP32 por medio de un paquete LMP reproducido (duplicado)"
}
],
"lastModified": "2026-06-17T03:45:51.807",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EFF8C3F9-F42A-48FF-ADBF-E09B7D7B5550",
"versionEndIncluding": "4.4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:espressif:esp32:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D1024B06-380B-4116-B7F9-A21A03534B0C"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}