5.4

CVE-2022-46401

Exploit

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.

Data is provided by the National Vulnerability Database (NVD)
MicrochipBm78 Firmware Version1.43
   MicrochipBm78 Version-
MicrochipBm83 Firmware Version1.43
   MicrochipBm83 Version-
MicrochipRn4870 Firmware Version1.43
   MicrochipRn4870 Version-
MicrochipRn4871 Firmware Version1.43
   MicrochipRn4871 Version-
MicrochipBm70 Firmware Version1.43
   MicrochipBm70 Version-
MicrochipBm71 Firmware Version1.43
   MicrochipBm71 Version-
MicrochipWbz451 Firmware Version-
   MicrochipWbz451 Version-
MicrochipRn4678 Firmware Version1.43
   MicrochipRn4678 Version-
MicrochipBm77 Firmware Version1.43
   MicrochipBm77 Version-
MicrochipBm64 Firmware Version1.43
   MicrochipBm64 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.211
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.8 2.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.4 2.8 2.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.