Csa-iot

Matter

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.41%
  • Veröffentlicht 14.07.2026 00:00:00
  • Zuletzt bearbeitet 17.07.2026 03:18:44

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server tick logic (`emberAfLevelControlClusterServerTickCallback`). When a MoveToLevel command is executed an...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 14.07.2026 00:00:00
  • Zuletzt bearbeitet 17.07.2026 03:10:14

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control cluster's periodic server tick logic. When a MoveToLevel command is sent and immediately followed by a write of Operati...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 14.07.2026 00:00:00
  • Zuletzt bearbeitet 17.07.2026 03:07:54

A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, TargetNavigator, etc.). The function lacks proper valida...

  • EPSS 0.33%
  • Veröffentlicht 14.07.2026 00:00:00
  • Zuletzt bearbeitet 17.07.2026 03:00:07

A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()` method is called without first checking whether a value exists. This leads to a crash when an InvokeComman...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 14.07.2026 00:00:00
  • Zuletzt bearbeitet 17.07.2026 03:19:43

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the code incorrec...

  • EPSS 0.21%
  • Veröffentlicht 24.07.2024 08:15:03
  • Zuletzt bearbeitet 21.11.2024 09:29:37

An implementation issue in the Connectivity Standards Alliance Matter 1.2 protocol as used in the connectedhomeip SDK allows a third party to disclose information about devices part of the same fabric (footprinting), even though the protocol is desig...

  • EPSS 0.15%
  • Veröffentlicht 24.07.2024 08:15:02
  • Zuletzt bearbeitet 21.11.2024 09:29:20

An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between two devices, as implemented in the Matter protocol versions before Matter 1.1 allows an attacker to replay manipulated CASE Sigma...