CVE-2022-46401

MEDIUM

Microchip RN4870 <1.43 - Buffer Overflow

Title source: llm
STIX 2.1

Description

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.

Scores

CVSS v3 5.4
EPSS 0.0066
EPSS Percentile 46.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (12)
microchip/bm64_firmware 1.43
microchip/bm70_firmware 1.43
microchip/bm71_firmware 1.43
microchip/bm77_firmware 1.43
microchip/bm78_firmware 1.43
microchip/bm83_firmware 1.43
microchip/pic32cx1012bz25048_firmware
microchip/pic_lightblue_explorer_demo_firmware 4.2_dt100112
microchip/rn4678_firmware 1.43
microchip/rn4870_firmware 1.43
... and 2 more
Published Dec 19, 2022
Tracked Since Feb 18, 2026