{"id":"PYSEC-2023-234","details":"An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm.","aliases":["CVE-2023-46894","GHSA-3f38-96qm-r3fw"],"modified":"2026-06-29T07:30:05.084111330Z","published":"2023-11-09T16:15:00Z","withdrawn":"2026-06-23T12:08:00Z","references":[{"type":"EVIDENCE","url":"https://github.com/espressif/esptool/issues/926"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3f38-96qm-r3fw"}],"affected":[{"package":{"name":"esptool","ecosystem":"PyPI","purl":"pkg:pypi/esptool"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.0","1.0.1","1.1","1.2","1.2.1","1.3","2.0","2.0.1","2.1","2.2","2.2.1","2.3","2.3.1","2.4.0","2.4.1","2.5.0","2.5.1","2.6","2.7","2.8","3.0","3.1","3.2","3.3","3.3.1","3.3.2","3.3.3","4.0","4.0.1","4.1","4.10.0","4.10.dev1","4.10.dev2","4.11.0","4.11.dev1","4.11.dev2","4.12.dev1","4.12.dev2","4.12.dev3","4.2","4.2.1","4.3","4.4","4.5","4.5.1","4.5.dev0","4.5.dev1","4.5.dev2","4.5.dev3","4.6","4.6.1","4.6.2","4.6.dev1","4.7.0","4.7.dev1","4.7.dev2","4.7.dev3","4.8.0","4.8.1","4.8.dev1","4.8.dev2","4.8.dev3","4.8.dev4","4.8.dev5","4.9.0","4.9.dev1","4.9.dev2","4.9.dev3","4.9.dev4","4.9.dev5","4.9.dev6","4.9.dev7","4.9.dev8","5.0.0","5.0.1","5.0.2","5.0.dev0","5.0.dev1","5.1.0","5.1.dev1","5.2.0","5.2.dev1","5.2.dev2","5.2.dev3","5.2.dev4","5.3.0","5.3.1","5.3.dev1","5.3.dev2","5.3.dev3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/esptool/PYSEC-2023-234.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}