CVE-2022-45191
https://notcve.org/view.php?id=CVE-2022-45191
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a pair confirm message with wrong values. • https://www.microchip.com/en-us/support/product-change-notification • CWE-354: Improper Validation of Integrity Check Value •
CVE-2022-45190
https://notcve.org/view.php?id=CVE-2022-45190
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device. • https://blediff.github.io • CWE-306: Missing Authentication for Critical Function •
CVE-2022-45192
https://notcve.org/view.php?id=CVE-2022-45192
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a cleartext encryption pause request. • https://blediff.github.io •
CVE-2022-46403
https://notcve.org/view.php?id=CVE-2022-46403
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages. El firmware 1.43 del módulo Microchip RN4870 (y la demostración 4.2 DT100112 de Microchip PIC LightBlue Explorer) maneja mal los mensajes de rechazo. • https://microchip.com https://www.computer.org/csdl/proceedings-article/sp/2023/933600a521/1He7Yja1AYM https://www.computer.org/csdl/proceedings/sp/2023/1He7WWuJExG https://www.microchip.com/en-us/products/wireless-connectivity/software-vulnerability-response/deviating-behaviors-in-bluetooth-le •
CVE-2022-46401
https://notcve.org/view.php?id=CVE-2022-46401
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete. El firmware 1.43 del módulo Microchip RN4870 (y la demostración 4.2 DT100112 de Microchip PIC LightBlue Explorer) acepta PauseEncReqPlainText antes de que se complete el emparejamiento. • https://microchip.com https://www.computer.org/csdl/proceedings-article/sp/2023/933600a521/1He7Yja1AYM https://www.computer.org/csdl/proceedings/sp/2023/1He7WWuJExG https://www.microchip.com/en-us/products/wireless-connectivity/software-vulnerability-response/deviating-behaviors-in-bluetooth-le •