VulnerabilityModified
CVE-2022-45190
An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device.
MEDIUM 5.3EPSS 0.26%
Does this matter?
Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- microchip/rn4870 firmware
- Source
- cve@mitre.org
References
- https://blediff.github.io/Technical Description, Third Party Advisory
- https://blediff.github.io/Technical Description, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.