Bluetooth Module Vulnerability in Microchip's RN4870 and PIC LightBlue Explorer
CVE-2022-46403

8.6HIGH

Key Information:

Vendor

Microchip

Vendor
CVE Published:
19 December 2022

What is CVE-2022-46403?

The RN4870 module firmware version 1.43 and the PIC LightBlue Explorer Demo version 4.2 DT100112 from Microchip are susceptible to vulnerabilities due to improper handling of reject messages in Bluetooth communication. This flaw can potentially lead to unauthorized access or manipulation of data transmitted over Bluetooth connections, impacting the overall security of devices utilizing this module. It is essential for users to update their firmware to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-46403 : Bluetooth Module Vulnerability in Microchip's RN4870 and PIC LightBlue Explorer