{"id":"CVE-2020-16146","details":"Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x through 4.0.1 has a Buffer Overflow in BluFi provisioning in btc_blufi_recv_handler function in blufi_prf.c. An attacker can send a crafted BluFi protocol Write Attribute command to characteristic 0xFF01. With manipulated packet fields, there is a buffer overflow.","modified":"2026-08-07T15:11:50.451776Z","published":"2021-01-12T03:15:12.687Z","references":[{"type":"ADVISORY","url":"https://github.com/espressif/esp-idf"},{"type":"ADVISORY","url":"https://github.com/pokerfacett/MY_CVE_CREDIT/blob/master/CVE-2020-16146.md"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/espressif/esp-idf","events":[{"introduced":"0"},{"last_affected":"8bca703467be0d5e43e2a3dce2ca7727ca826474"},{"last_affected":"4c81978a3e2220674a432a588292a4c860eef27b"},{"introduced":"3f8f618df5157906e2ebe65f94b003e3ac1b82a7"},{"last_affected":"f3704f027e70a370bed3852f39c2ce48b9e8c7dc"},{"introduced":"22489d70214a5b7650ab197ffd6ab73e9c50a772"},{"last_affected":"d8e057b02c6ecf27b12a36a91a39bc506554f1f8"},{"introduced":"4b91c82cc447640e5b61407e810f1d6f3eabd233"},{"last_affected":"ca1e5e5bc52182a577f1706c8dcbb4d9d7afe310"},{"introduced":"c18890875e64de59581dc1bfe5fd094b262a7dc4"},{"last_affected":"9e70825d1e1cbf7988cf36981774300066580ea7"}],"database_specific":{"extracted_events":[{"introduced":"2.0.0"},{"last_affected":"2.1.1"},{"introduced":"4.0.0"},{"last_affected":"4.0.1"},{"introduced":"3.0"},{"last_affected":"3.0.9"},{"introduced":"3.1"},{"last_affected":"3.1.7"},{"introduced":"3.2"},{"last_affected":"3.2.3"},{"introduced":"3.3"},{"last_affected":"3.3.2"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:*"}}],"versions":["v4.0.1","v3.1.7","v3.3.2","v4.0-rc","v4.0","v3.3.1","v4.0-beta2","v3.0.9","v3.1.6","v3.2.3","v3.3","v4.0-beta1","v3.3-rc","v3.1.5","v3.2.2","v3.0.8","v3.2.1","v3.3-beta3","v3.1.4","v3.2-rc","v3.2","v4.0-dev","v3.3-beta2","v3.2-beta3","v3.1.3","v3.1.2","v3.0.7-rc","v3.0.7","v3.3-beta1","v3.2-beta1","v3.1.1","v3.0.6","v3.0.6-rc","v3.3-dev","v3.1.1-rc2","v3.0.5-rc","v3.0.5","v3.0.4-rc1","v3.0.4","v3.1-rc2","v3.1","v3.1-rc1","v3.0.3-rc","v3.0.3","v3.0.2","v3.1-beta1","v3.2-dev","v3.0.1-rc","v3.0.1","v3.0","v2.1.1","v3.0-rc1","v3.1-dev","v2.1","v2.1-rc1","v2.0-rc1","v1.0","v0.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-16146.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}