PT-2024-22772 · Microchip · Microchip Rn4870

Tianwei

+1

·

Published

2024-10-16

·

Updated

2024-10-16

·

CVE-2024-29155

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Microchip RN4870 (affected versions not specified)
Description The issue occurs when more than one consecutive PairReqNoInputNoOutput request is received, causing the device to become incapable of completing the pairing process. A third party can inject a second PairReqNoInputNoOutput request just after a real one, blocking the pair request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-29155

Affected Products

Microchip Rn4870