CVE-2022-46402
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/12/2022
Last modified:
17/04/2025
Description
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_rmSend with incorrect values.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:microchip:bm78_firmware:1.43:*:*:*:*:*:*:* | ||
| cpe:2.3:h:microchip:bm78:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microchip:bm83_firmware:1.43:*:*:*:*:*:*:* | ||
| cpe:2.3:h:microchip:bm83:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microchip:rn4870_firmware:1.43:*:*:*:*:*:*:* | ||
| cpe:2.3:h:microchip:rn4870:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microchip:rn4871_firmware:1.43:*:*:*:*:*:*:* | ||
| cpe:2.3:h:microchip:rn4871:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microchip:bm70_firmware:1.43:*:*:*:*:*:*:* | ||
| cpe:2.3:h:microchip:bm70:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microchip:bm71_firmware:1.43:*:*:*:*:*:*:* | ||
| cpe:2.3:h:microchip:bm71:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microchip:pic_lightblue_explorer_demo_firmware:4.2_dt100112:*:*:*:*:*:*:* | ||
| cpe:2.3:h:microchip:pic_lightblue_explorer_demo:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microchip:is1870_firmware:1.43:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://microchip.com
- https://www.computer.org/csdl/proceedings-article/sp/2023/933600a521/1He7Yja1AYM
- https://www.computer.org/csdl/proceedings/sp/2023/1He7WWuJExG
- https://www.microchip.com/en-us/products/wireless-connectivity/software-vulnerability-response/deviating-behaviors-in-bluetooth-le
- https://microchip.com
- https://www.computer.org/csdl/proceedings-article/sp/2023/933600a521/1He7Yja1AYM
- https://www.computer.org/csdl/proceedings/sp/2023/1He7WWuJExG
- https://www.microchip.com/en-us/products/wireless-connectivity/software-vulnerability-response/deviating-behaviors-in-bluetooth-le



