CVE-2022-47100: Input Validation
Published Jan 24, 2023
·Updated
A vulnerability in Sengled Smart bulb 0x0000024 allows attackers to arbitrarily perform a factory reset on the device via a crafted IEEE 802.15.4 frame.
Affected Software
4 affected components
Sengled Es21-n1eaw Firmware=0x0000024
Sengled Es21-n1eaw
All of the following
Sengled Es21-n1eaw Firmware=0x0000024
Sengled Es21-n1eaw
Event History
Jan 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-47100?
CVE-2022-47100 has a high severity level due to unauthorized factory reset functionality.
2
How do I fix CVE-2022-47100?
To fix CVE-2022-47100, ensure that your Sengled Smart bulb firmware is updated to a version that addresses this vulnerability.
3
What type of attack does CVE-2022-47100 expose the device to?
CVE-2022-47100 exposes the device to arbitrary factory reset attacks via crafted IEEE 802.15.4 frames.
4
Which devices are affected by CVE-2022-47100?
The vulnerability affects the Sengled ES21-N1EAW Smart bulb with firmware version 0x0000024.
5
Can CVE-2022-47100 affect other versions of Sengled Smart bulbs?
CVE-2022-47100 specifically targets Sengled Smart bulbs running firmware version 0x0000024, other versions may not be affected.