Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-3297

Опубликовано: 24 июл. 2024
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between two devices, as implemented in the Matter protocol versions before Matter 1.1 allows an attacker to replay manipulated CASE Sigma1 messages to make the device unresponsive until the device is power-cycled.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:csa-iot:matter:-:*:*:*:*:*:*:*

EPSS

Процентиль: 25%
0.00085
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 6.5
github
больше 1 года назад

An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between two devices, as implemented in the Matter protocol versions before Matter 1.1 allows an attacker to replay manipulated CASE Sigma1 messages to make the device unresponsive until the device is power-cycled.

EPSS

Процентиль: 25%
0.00085
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400
NVD-CWE-noinfo