The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.

Project Subscriptions

Vendors Products
Microchip Subscribe
Bm64 Firmware Subscribe
Bm70 Firmware Subscribe
Bm71 Firmware Subscribe
Bm77 Firmware Subscribe
Bm78 Firmware Subscribe
Bm83 Firmware Subscribe
Pic32cx1012bz25048 Subscribe
Pic32cx1012bz25048 Firmware Subscribe
Pic Lightblue Explorer Demo Subscribe
Pic Lightblue Explorer Demo Firmware Subscribe
Rn4678 Firmware Subscribe
Rn4870 Firmware Subscribe
Rn4871 Firmware Subscribe
Wbz451 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-49210 The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 17 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-04-17T14:29:14.157Z

Reserved: 2022-12-04T00:00:00.000Z

Link: CVE-2022-46401

cve-icon Vulnrichment

Updated: 2024-08-03T14:31:46.373Z

cve-icon NVD

Status : Modified

Published: 2022-12-19T23:15:11.017

Modified: 2025-04-17T15:15:51.693

Link: CVE-2022-46401

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses