PT-2021-21734 · Microchip · Microchip Miwi

Published

2021-08-05

·

Updated

2022-07-12

·

CVE-2021-37605

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microchip MiWi software versions prior to 6.5
Description The issue concerns the validation of Message Integrity Check (MIC) bytes in the Microchip MiWi software stack. Specifically, the stack only validates two out of four MIC bytes. Additionally, there is a possibility of frame counters being validated or updated before message authentication, which could lead to security issues.
Recommendations For Microchip MiWi software versions prior to 6.5, update to a version that properly validates all four MIC bytes and ensures message authentication occurs before frame counter validation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37605

Affected Products

Microchip Miwi