5.4

CVE-2022-46400

Exploit

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing.

Data is provided by the National Vulnerability Database (NVD)
MicrochipBm78 Firmware Version1.43
   MicrochipBm78 Version-
MicrochipBm83 Firmware Version1.43
   MicrochipBm83 Version-
MicrochipRn4870 Firmware Version1.43
   MicrochipRn4870 Version-
MicrochipRn4871 Firmware Version1.43
   MicrochipRn4871 Version-
MicrochipBm70 Firmware Version1.43
   MicrochipBm70 Version-
MicrochipBm71 Firmware Version1.43
   MicrochipBm71 Version-
MicrochipIs1870 Firmware Version1.43
   MicrochipIs1870 Version-
MicrochipIs1871 Firmware Version1.43
   MicrochipIs1871 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.074
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.8 2.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.4 2.8 2.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.