CVE Watcher
Sitemap Privacy Security.txt Open CVE Console

Shareable CVE page

CVE-2026-45328

This is the local share page for this CVE/source combination.

CVE-2026-45328

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c that bridge calls from the user application (i.e. the REE) to TEE-protected hardware peripherals (AES, SHA, ECC, HMAC, SPI, MMU, WDT) and to the security feature like attestation, OTA updates, secure storage. This issue has been patched in versions 5.5.5 and 6.0.1.

critical
SourceCVE List v5 CVSS9.3 Severitycritical Published2026-06-10 EPSSn/a
Open in CVE Console
Vector and technical detailsCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H