CVE-2022-46401

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
microchipbm78_firmware
1.43
microchipbm83_firmware
1.43
microchiprn4870_firmware
1.43
microchiprn4871_firmware
1.43
microchipbm70_firmware
1.43
microchipbm71_firmware
1.43
microchippic_lightblue_explorer_demo_firmware
4.2_dt100112:_dt100112
microchippic32cx1012bz25048_firmware
-
microchipwbz451_firmware
-
microchiprn4678_firmware
1.43
microchipbm77_firmware
1.43
microchipbm64_firmware
1.43
𝑥
= Vulnerable software versions