PT-2024-36788 · Matter · Matter

Bob13

·

Published

2024-12-18

·

Updated

2024-12-31

·

CVE-2024-56319

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Matter (aka connectedhomeip or Project CHIP) versions 1.4.0.0 and earlier, before e3277eb
Description The issue is related to unlimited user label appends in a userlabel cluster, which can lead to a denial of service due to resource exhaustion.
Recommendations For Matter (aka connectedhomeip or Project CHIP) versions 1.4.0.0 and earlier, before e3277eb, consider restricting the number of user label appends in a userlabel cluster to prevent resource exhaustion until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-56319

Affected Products

Matter