Lucene search

K
nvd[email protected]NVD:CVE-2022-45190
HistoryFeb 08, 2023 - 12:15 a.m.

CVE-2022-45190

2023-02-0800:15:08
CWE-306
web.nvd.nist.gov
4
microchip
rn4870
ble
passkey
bypass
pairing

CVSS3

5.3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

20.9%

An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device.

Affected configurations

Nvd
Node
microchiprn4870Match-
AND
microchiprn4870_firmwareMatch1.43
VendorProductVersionCPE
microchiprn4870-cpe:2.3:h:microchip:rn4870:-:*:*:*:*:*:*:*
microchiprn4870_firmware1.43cpe:2.3:o:microchip:rn4870_firmware:1.43:*:*:*:*:*:*:*

CVSS3

5.3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

20.9%

Related for NVD:CVE-2022-45190