nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-29155 CVE-2024-29155
MEDIUM
Denial of service on Microchip RN4870 devices
Record summary
CVE-2024-29155 has a selected CVSS score of 4.3 (medium).
Description
On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device becomes incapable of completing the pairing process. A third party can inject a second PairReqNoInputNoOutput request just after a real one, causing the pair request to be blocked.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 16, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 1.44 | affected |
References
3ww1.microchip.comrelease notesproductTechnical description
https://ww1.microchip.com/downloads/aemDocuments/documents/WSG/ProductDocuments/SoftwareLibraries/Firmware/RN4870-71-Firmware-1.44.zip microchip.comproduct
https://www.microchip.com/en-us/product/rn4870