CVE Vulnerabilities

CVE-2022-46401

Published: Dec 19, 2022 | Modified: Dec 27, 2022
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.

Affected Software

Name Vendor Start Version End Version
Bm78_firmware Microchip 1.43 (including) 1.43 (including)

References