ESP32/ESP8266 (CVE-2019-12586) and (CVE-2019-12587)
-
hi all,
Look like core code must be updated asap.
Patch
https://github.com/espressif/esp-idf/commit/8009320fb44abaf8acf8a1e1a38a67fc4c8d458cESP32/ESP8266 EAP client crash (CVE-2019-12586)
Crashing ESP devices connected to enterprise networksAnd another
Zero PMK Installation (CVE-2019-12587)
Hijacking ESP32/ESP8266 clients connected to enterprise networks