CVE-2022-45190

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
08/02/2023
Last modified:
25/03/2025

Description

An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:microchip:rn4870_firmware:1.43:*:*:*:*:*:*:*
cpe:2.3:h:microchip:rn4870:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools