5.4
CVE-2022-46401
- EPSS 0.66%
- Veröffentlicht 19.12.2022 23:15:11
- Zuletzt bearbeitet 17.04.2025 15:15:51
- Erkennungen
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microchip ≫ Bm78 Firmware Version 1.43
Microchip ≫ Bm83 Firmware Version 1.43
Microchip ≫ Rn4870 Firmware Version 1.43
Microchip ≫ Rn4871 Firmware Version 1.43
Microchip ≫ Bm70 Firmware Version 1.43
Microchip ≫ Bm71 Firmware Version 1.43
Microchip ≫ Pic Lightblue Explorer Demo Firmware Version 4.2_dt100112
Microchip ≫ Pic32cx1012bz25048 Firmware Version -
Microchip ≫ Wbz451 Firmware Version -
Microchip ≫ Rn4678 Firmware Version 1.43
Microchip ≫ Bm77 Firmware Version 1.43
Microchip ≫ Bm64 Firmware Version 1.43
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.66% | 0.466 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
|
| CISA-ADP | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://microchip.com
https://www.computer.org/csdl/proceedings-article/sp/2023/933600a521/1He7Yja1AYM
https://www.computer.org/csdl/proceedings/sp/2023/1He7WWuJExG
https://www.microchip.com/en-us/products/wireless-connectivity/software-vulnerability-response/deviating-behaviors-in-bluetooth-le