VYPR

Rn4870 Firmware

by Microchip

CVEs (8)

  • CVE-2022-46403HigDec 19, 2022
    risk 0.56cvss 8.6epss 0.01

    The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages.

  • CVE-2022-46399HigDec 19, 2022
    risk 0.49cvss 7.5epss 0.01

    The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero.

  • CVE-2022-45192MedFeb 8, 2023
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a cleartext encryption pause request.

  • CVE-2022-45191MedFeb 8, 2023
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a pair confirm message with wrong values.

  • CVE-2022-46402MedDec 19, 2022
    risk 0.42cvss 6.5epss 0.00

    The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_rmSend with incorrect values.

  • CVE-2022-46401MedDec 19, 2022
    risk 0.35cvss 5.4epss 0.01

    The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.

  • CVE-2022-46400MedDec 19, 2022
    risk 0.35cvss 5.4epss 0.01

    The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing.

  • CVE-2022-45190MedFeb 8, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device.