Vulnerability Description
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the code incorrectly treats the endpoint as valid due to missing checks in CodegenDataModelProvider::Invoke. This causes a VerifyOrDie failure in ProcessCommandDataIB and results in a crash (SIGABRT). The issue has been acknowledged and fixed in a later revision (PR #37207).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Csa-Iot | Matter | < 1.4.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/project-chip/connectedhomeip/Product
- https://github.com/project-chip/connectedhomeip/issues/37184ExploitIssue Tracking
- https://github.com/project-chip/connectedhomeip/pull/37207Patch
- https://github.com/project-chip/connectedhomeip/issues/37184ExploitIssue Tracking
FAQ
What is CVE-2025-56365?
CVE-2025-56365 is a vulnerability with a CVSS score of 7.5 (HIGH). A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent en...
How severe is CVE-2025-56365?
CVE-2025-56365 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-56365?
Check the references section above for vendor advisories and patch information. Affected products include: Csa-Iot Matter.