CVE-2024-29155
Last modified
CVE-2024-29155 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device becomes incapable of completing the pairing process. A third party can inject a second PairReqNoInputNoOutput request just after a real one, causing the pair request to be blocked.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device becomes incapable of completing the pairing process. A third party can inject a second PairReqNoInputNoOutput request just after a real one, causing the pair request to be blocked.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-29155?
How severe is CVE-2024-29155?
How do I fix CVE-2024-29155?
Are you affected by CVE-2024-29155?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
