Bugzilla – Bug 1217006
VUL-0: CVE-2023-46894: python-esptool: inadequate encryption strength
Last modified: 2023-11-13 04:20:52 UTC
An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-46894
@Stoyan, please see https://github.com/espressif/esptool/issues/926 - this is a hardening issue and not fixable in software as the bootloader is in ROM.