Message Integrity Check Vulnerability in Microchip MiWi Software
CVE-2021-37605
7.5HIGH
What is CVE-2021-37605?
In version 6.5 of Microchip's MiWi software, as well as all prior versions, a significant issue has been identified concerning the validation of Message Integrity Check (MIC) bytes. The software currently only validates two out of the expected four MIC bytes, rendering it susceptible to integrity verification failures. This compromised validation process can potentially allow attackers to interfere with the integrity of the communications within supported devices, thereby undermining the security of wireless protocols utilizing this software.