Vulnerability Description
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microchip | Bm78 Firmware | 1.43 |
| Microchip | Bm78 | - |
| Microchip | Bm83 Firmware | 1.43 |
| Microchip | Bm83 | - |
| Microchip | Rn4870 Firmware | 1.43 |
| Microchip | Rn4870 | - |
| Microchip | Rn4871 Firmware | 1.43 |
| Microchip | Rn4871 | - |
| Microchip | Bm70 Firmware | 1.43 |
| Microchip | Bm70 | - |
| Microchip | Bm71 Firmware | 1.43 |
| Microchip | Bm71 | - |
| Microchip | Pic Lightblue Explorer Demo Firmware | 4.2_dt100112 |
| Microchip | Pic Lightblue Explorer Demo | - |
| Microchip | Is1870 Firmware | 1.43 |
| Microchip | Is1870 | - |
| Microchip | Is1871 Firmware | 1.43 |
| Microchip | Is1871 | - |
Related Weaknesses (CWE)
References
- https://microchip.comProduct
- https://www.computer.org/csdl/proceedings-article/sp/2023/933600a521/1He7Yja1AYMExploitTechnical DescriptionThird Party Advisory
- https://www.computer.org/csdl/proceedings/sp/2023/1He7WWuJExGThird Party Advisory
- https://www.microchip.com/en-us/products/wireless-connectivity/software-vulnerabVendor Advisory
- https://microchip.comProduct
- https://www.computer.org/csdl/proceedings-article/sp/2023/933600a521/1He7Yja1AYMExploitTechnical DescriptionThird Party Advisory
- https://www.computer.org/csdl/proceedings/sp/2023/1He7WWuJExGThird Party Advisory
- https://www.microchip.com/en-us/products/wireless-connectivity/software-vulnerabVendor Advisory
FAQ
What is CVE-2022-46400?
CVE-2022-46400 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing.
How severe is CVE-2022-46400?
CVE-2022-46400 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-46400?
Check the references section above for vendor advisories and patch information. Affected products include: Microchip Bm78 Firmware, Microchip Bm78, Microchip Bm83 Firmware, Microchip Bm83, Microchip Rn4870 Firmware.