CVE-2024-53406: Espressif Esp-Idf
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a previous connection session, creating an opportunity for attackers to execute security bypass attacks.
Affected products
- Espressif Esp-Idf: version 5.3 only
Published 2025-03-13. Last modified 2026-06-17.