MEDIUM
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete
Published Dec 19, 2022
5.4
MEDIUMCVSS 3.1
EPSS 0.68%
Description
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.
Affected products
No data.
Configuration 1
AND
- 1.43
Configuration 2
AND
- 1.43
Configuration 3
AND
- 1.43
Configuration 4
AND
- 1.43
Configuration 5
AND
- 1.43
Configuration 6
AND
- 1.43
Configuration 7
AND
- 4.2_dt100112
Running on/with
- n/a
Configuration 8
AND
- n/a
Running on/with
- n/a
Configuration 9
AND
- n/a
Configuration 10
AND
- 1.43
Configuration 11
AND
- 1.43
Configuration 12
AND
- 1.43
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-49210 Advisory
- https://microchip.com Product
- https://www.computer.org/csdl/proceedings-article/sp/2023/933600a521/1He7Yja1AYM ExploitTechnical DescriptionThird Party Advisory
- https://www.computer.org/csdl/proceedings/sp/2023/1He7WWuJExG Third Party Advisory
- https://www.microchip.com/en-us/products/wireless-connectivity/software-vulnerability-response/deviating-behaviors-in-bluetooth-le Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-49210 | Advisory | |
| https://microchip.com | Product | |
| https://www.computer.org/csdl/proceedings-article/sp/2023/933600a521/1He7Yja1AYM | ExploitTechnical DescriptionThird Party Advisory | |
| https://www.computer.org/csdl/proceedings/sp/2023/1He7WWuJExG | Third Party Advisory | |
| https://www.microchip.com/en-us/products/wireless-connectivity/software-vulnerability-response/deviating-behaviors-in-bluetooth-le | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 19, 2022
Updated Apr 17, 2025
Reserved Dec 4, 2022
Link CVE-2022-46401
CISA Vulnrichment
Updated Apr 17, 2025
Red Hat
No data
GitHub
No data