CVE-2024-29155: Denial of service on Microchip RN4870 devices
On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device becomes incapable of completing the pairing process. A third party can inject a second PairReqNoInputNoOutput request just after a real one, causing the pair request to be blocked.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29155?
The severity of CVE-2024-29155 is rated as high due to the potential for an attacker to disrupt the pairing process of affected Microchip RN4870 devices.
How do I fix CVE-2024-29155?
To fix CVE-2024-29155, users should update the firmware of their Microchip RN4870 devices to the latest version available from Microchip.
Which devices are affected by CVE-2024-29155?
CVE-2024-29155 specifically affects Microchip RN4870 devices that handle PairReqNoInputNoOutput requests.
What impact does CVE-2024-29155 have on device functionality?
CVE-2024-29155 can prevent the RN4870 device from completing the pairing process, potentially causing communication failures.
Is there any workaround for CVE-2024-29155?
Currently, there are no documented workarounds for CVE-2024-29155, making firmware updates the primary mitigation.