Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hw2r-jgp3-3h2v

Опубликовано: 16 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device becomes incapable of completing the pairing process. A third party can inject a second PairReqNoInputNoOutput request just after a real one, causing the pair request to be blocked.

On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device becomes incapable of completing the pairing process. A third party can inject a second PairReqNoInputNoOutput request just after a real one, causing the pair request to be blocked.

EPSS

Процентиль: 25%
0.00087
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-20
CWE-239

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device becomes incapable of completing the pairing process. A third party can inject a second PairReqNoInputNoOutput request just after a real one, causing the pair request to be blocked.

EPSS

Процентиль: 25%
0.00087
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-20
CWE-239