CVE-2024-29155CWE-239

Denial of service on Microchip RN4870 devices

Medium · published October 16, 2024

CVSS v3.1
4.3
EPSS
0%
Percentile
14.2
In the wild
Unconfirmed
What it is

On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is

received, the device becomes incapable of completing the pairing

process. A third party can inject a second PairReqNoInputNoOutput request

just after a real one, causing the pair request to be blocked.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS v4.0
Not supplied
EPSS
0.00234 · 14.2th percentile
Weakness
CWE-239 · Failure to Handle Incomplete Element
Published
2024-10-16T15:51Z
EPSS history
Timeline
  • 16 OCT 15:51Z
    Denial of service on Microchip RN4870 devices
    cvelistv5