Firmware Vulnerability in Microchip RN4870 Module and LightBlue Explorer Demo
CVE-2022-46401
5.4MEDIUM
What is CVE-2022-46401?
The Microchip RN4870 module firmware version 1.43 and the LightBlue Explorer Demo 4.2 DT100112 exhibit a vulnerability where the device can accept a PauseEncReqPlainText message prior to the completion of the pairing process. This situation may expose the module to potential security risks as it can lead to unintended interactions and may allow attackers to inject malicious commands during the initialization phase of the Bluetooth connection.