CVE-2024-3454

LOW

Csa-iot Matter - Error Information Exposure

Title source: rule
STIX 2.1

Description

An implementation issue in the Connectivity Standards Alliance Matter 1.2 protocol as used in the connectedhomeip SDK allows a third party to disclose information about devices part of the same fabric (footprinting), even though the protocol is designed to prevent access to such information.

Scores

CVSS v3 3.5
EPSS 0.0011
EPSS Percentile 28.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (1)
csa-iot/matter
Published Jul 24, 2024
Tracked Since Feb 18, 2026