CVE-2025-68473

NONE EPSS 29.5%
Published Dec 27, 20256mo ago · Modified Jun 17, 20261w ago
0.0 CVSS 4.0
Low
Find Similar
Published Dec 27, 2025 6mo ago
Last Modified Jun 17, 2026 1w ago

Description

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, in the ESP-IDF Bluetooth host stack (BlueDroid), the function bta_dm_sdp_result() used a fixed-size array uuid_list[32][MAX_UUID_SIZE] to store discovered service UUIDs during the SDP (Service Discovery Protocol) process. On modern Bluetooth devices, it is possible for the number of available services to exceed this fixed limit (32). In such cases, if more than 32 services are discovered, subsequent writes to uuid_list could exceed the bounds of the array, resulting in a potential out-of-bounds write condition.

CVSS Details

Base Score
0.0
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
29.5% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-787 Out-of-bounds Write Memory Safety

Affected Products 5

VendorProductVersionRange
espressifesp-idf5.1.6any
espressifesp-idf5.2.6any
espressifesp-idf5.3.4any
espressifesp-idf5.4.3any
espressifesp-idf5.5.1any

References 8

  • github.com https://github.com/espressif/esp-idf/commit/3286e45349b0b5c2b1422ef7e8d088b95eef895d
    Patch
  • github.com https://github.com/espressif/esp-idf/commit/4d928f2265c394d2abc85024228e920a5b26bcab
    Patch
  • github.com https://github.com/espressif/esp-idf/commit/5b3185168dae83d42aa0852689422fffd931f16c
    Patch
  • github.com https://github.com/espressif/esp-idf/commit/6453f57a954458ad8ffd6e4bf2d9e76b73fac0f1
    Patch
  • github.com https://github.com/espressif/esp-idf/commit/6ca6f422dafaffcb88fa56cc458ce92d96be3b2e
    Patch
  • github.com https://github.com/espressif/esp-idf/commit/9889edd799cf369e082df9d01adba961d64693ed
    Patch
  • github.com https://github.com/espressif/esp-idf/commit/ecb86d353640cf1375bf97db32e702ba59c551b6
    Patch
  • github.com https://github.com/espressif/esp-idf/security/advisories/GHSA-hmjj-rjvv-w8pq
    MitigationVendor Advisory

Remediation

  • github.com https://github.com/espressif/esp-idf/commit/3286e45349b0b5c2b1422ef7e8d088b95eef895d
    Patch
  • github.com https://github.com/espressif/esp-idf/commit/4d928f2265c394d2abc85024228e920a5b26bcab
    Patch
  • github.com https://github.com/espressif/esp-idf/commit/5b3185168dae83d42aa0852689422fffd931f16c
    Patch
  • github.com https://github.com/espressif/esp-idf/commit/6453f57a954458ad8ffd6e4bf2d9e76b73fac0f1
    Patch
  • github.com https://github.com/espressif/esp-idf/commit/6ca6f422dafaffcb88fa56cc458ce92d96be3b2e
    Patch
  • github.com https://github.com/espressif/esp-idf/commit/9889edd799cf369e082df9d01adba961d64693ed
    Patch
  • github.com https://github.com/espressif/esp-idf/commit/ecb86d353640cf1375bf97db32e702ba59c551b6
    Patch