PT-2021-21734 · Microchip · Microchip Miwi
Published
2021-08-05
·
Updated
2022-07-12
·
CVE-2021-37605
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Microchip MiWi software versions prior to 6.5
Description
The issue concerns the validation of Message Integrity Check (MIC) bytes in the Microchip MiWi software stack. Specifically, the stack only validates two out of four MIC bytes. Additionally, there is a possibility of frame counters being validated or updated before message authentication, which could lead to security issues.
Recommendations
For Microchip MiWi software versions prior to 6.5, update to a version that properly validates all four MIC bytes and ensures message authentication occurs before frame counter validation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Microchip Miwi