CVE-2022-46400: Medium severity microchip bm78 firmware vulnerability
Published Dec 19, 2022
·Updated
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing.
Affected Software
36 affected components
Microchip Bm78 Firmware=1.43
Microchip Bm78
Microchip Bm83 Firmware=1.43
Microchip Bm83
Microchip Rn4870 Firmware=1.43
Microchip RN4870
Microchip Rn4871 Firmware=1.43
Microchip Rn4871
Microchip Bm70 Firmware=1.43
Microchip Bm70
Microchip Bm71 Firmware=1.43
Microchip Bm71
Microchip Pic Lightblue Explorer Demo Firmware=4.2_dt100112
Microchip PIC LightBlue Explorer Demo
Microchip Is1870 Firmware=1.43
Microchip Is1870
Microchip Is1871 Firmware=1.43
Microchip Is1871
All of the following
Microchip Bm78 Firmware=1.43
Microchip Bm78
All of the following
Microchip Bm83 Firmware=1.43
Microchip Bm83
All of the following
Microchip Rn4870 Firmware=1.43
Microchip RN4870
All of the following
Microchip Rn4871 Firmware=1.43
Microchip Rn4871
All of the following
Microchip Bm70 Firmware=1.43
Microchip Bm70
All of the following
Microchip Bm71 Firmware=1.43
Microchip Bm71
All of the following
Microchip Pic Lightblue Explorer Demo Firmware=4.2_dt100112
Microchip PIC LightBlue Explorer Demo
All of the following
Microchip Is1870 Firmware=1.43
Microchip Is1870
All of the following
Microchip Is1871 Firmware=1.43
Microchip Is1871
Event History
Dec 19, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-46400.
2
What is the severity level of CVE-2022-46400?
The severity level of CVE-2022-46400 is medium with a CVSS score of 5.4.
3
Which software versions are affected by CVE-2022-46400?
The Microchip RN4870 module firmware 1.43 and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112 are affected by CVE-2022-46400.
4
How can attackers exploit CVE-2022-46400?
Attackers can exploit CVE-2022-46400 to bypass passkey entry in legacy pairing.
5
Are there any references available for CVE-2022-46400?
Yes, you can find references for CVE-2022-46400 at the following links: [link1], [link2], [link3].