CVE-2022-46401: Input Validation
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-46401?
CVE-2022-46401 is a vulnerability in the Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) that allows the acceptance of PauseEncReqPlainText before pairing is complete.
How severe is CVE-2022-46401?
CVE-2022-46401 has a severity level of medium, with a CVSS score of 5.4.
Which software versions are affected by CVE-2022-46401?
The Microchip RN4870 module firmware version 1.43 is affected by CVE-2022-46401.
How can I fix CVE-2022-46401?
Currently, there is no official fix for CVE-2022-46401. It is recommended to follow the security guidelines provided by Microchip and stay updated with any patches or firmware updates they release.
Where can I find more information about CVE-2022-46401?
You can find more information about CVE-2022-46401 on the microchip.com website and in the proceedings articles published by Computer.org.