VYPR
Vendor

Project Chip

Products
3
CVEs
9
Across products
11
Status
Private

Products

3

Recent CVEs

9
  • CVE-2023-42189HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote…

  • CVE-2024-56319HigDec 18, 2024
    risk 0.42cvss 7.5epss 0.01

    In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a denial of service (resource exhaustion).

  • CVE-2024-56318HigDec 18, 2024
    risk 0.42cvss 7.5epss 0.01

    In raw\TCP.cpp in Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before 27ca6ec, there is a NULL pointer dereference in TCPBase::ProcessSingleMessage via TCP packets with zero messageSize, leading to denial of service.

  • CVE-2024-56317HigDec 18, 2024
    risk 0.42cvss 7.5epss 0.00

    In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes all existing ACL entries first, and then attempts to recreate them based on user input. If input validation fails during decoding, the process stops, and no entries are restored by…

  • CVE-2025-56365HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the code incorrectly treats the endpoint as…

  • CVE-2025-56364HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()` method is called without first checking whether a value exists. This leads to a crash when an InvokeCommand is sent without…

  • CVE-2025-56363HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, TargetNavigator, etc.). The function lacks proper validation of the delegate pointer…

  • CVE-2025-56362HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control cluster's periodic server tick logic. When a MoveToLevel command is sent and immediately followed by a write of OperationMode=2 (in the Pump…

  • CVE-2025-56361HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server tick logic (`emberAfLevelControlClusterServerTickCallback`). When a MoveToLevel command is executed and followed by a conflicting…