SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-46401

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.

MEDIUM 5.4EPSS 0.66%

Does this matter?

Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.

Description

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
EPSS
0.66% probability · 50th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
microchip/bm78 firmware · microchip/bm83 firmware · microchip/rn4870 firmware · microchip/rn4871 firmware · microchip/bm70 firmware · microchip/bm71 firmware · microchip/pic lightblue explorer demo firmware · microchip/pic32cx1012bz25048 firmware · microchip/wbz451 firmware · microchip/rn4678 firmware · microchip/bm77 firmware · microchip/bm64 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.