Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-46400


The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing.


Published

2022-12-19T23:15:10.960

Last Modified

2025-04-17T15:15:51.150

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System microchip bm78_firmware 1.43 Yes
Hardware microchip bm78 - No
Operating System microchip bm83_firmware 1.43 Yes
Hardware microchip bm83 - No
Operating System microchip rn4870_firmware 1.43 Yes
Hardware microchip rn4870 - No
Operating System microchip rn4871_firmware 1.43 Yes
Hardware microchip rn4871 - No
Operating System microchip bm70_firmware 1.43 Yes
Hardware microchip bm70 - No
Operating System microchip bm71_firmware 1.43 Yes
Hardware microchip bm71 - No
Operating System microchip pic_lightblue_explorer_demo_firmware 4.2_dt100112 Yes
Hardware microchip pic_lightblue_explorer_demo - No
Operating System microchip is1870_firmware 1.43 Yes
Hardware microchip is1870 - No
Operating System microchip is1871_firmware 1.43 Yes
Hardware microchip is1871 - No

References