Vulnerability Description
A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()` method is called without first checking whether a value exists. This leads to a crash when an InvokeCommand is sent without initializing the destination group ID. The issue affects all versions before commit 0360cc3 (Dec 5, 2024) and leads to denial of service through SIGABRT. It is fixed by adding a .HasValue() check before access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Csa-Iot | Matter | < 1.4.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/project-chip/connectedhomeip/Product
- https://github.com/project-chip/connectedhomeip/issues/36711Issue Tracking
- https://github.com/project-chip/connectedhomeip/pull/36729Patch
- https://github.com/project-chip/connectedhomeip/issues/36711Issue Tracking
FAQ
What is CVE-2025-56364?
CVE-2025-56364 is a vulnerability with a CVSS score of 7.5 (HIGH). A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()` method is called without first checking whether a value ...
How severe is CVE-2025-56364?
CVE-2025-56364 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-56364?
Check the references section above for vendor advisories and patch information. Affected products include: Csa-Iot Matter.