Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Microchip Subscribe
Filtered by product Miwi
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-37604 1 Microchip 1 Miwi 2022-07-12 5.0 MEDIUM 7.5 HIGH
In version 6.5 of Microchip MiWi software and all previous versions including legacy products, there is a possibility of frame counters being validated/updated prior to the message authentication. With this vulnerability in place, an attacker may increment the incoming frame counter values by injecting messages with a sufficiently large frame counter value and invalid payload. This results in denial of service/valid packets in the network. There is also a possibility of a replay attack in the stack.
CVE-2021-37605 1 Microchip 1 Miwi 2022-07-12 5.0 MEDIUM 7.5 HIGH
In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Message Integrity Check (MIC) bytes.