CVE-2025-56365
גבוהה 7.5
תיאור (מקור, אנגלית)
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the code incorrectly treats the endpoint as valid due to missing checks in CodegenDataModelProvider::Invoke. This causes a VerifyOrDie failure in ProcessCommandDataIB and results in a crash (SIGABRT). The issue has been acknowledged and fixed in a later revision (PR #37207).
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-8/8/2026
- CWE
- CWE-617
מוצרים מושפעים
csa-iot: matter
קישורים
- https://github.com/project-chip/connectedhomeip/pull/37207 Patch
- https://github.com/project-chip/connectedhomeip/issues/37184 ExploitIssue Tracking
- https://github.com/project-chip/connectedhomeip/issues/37184 ExploitIssue Tracking
- https://github.com/project-chip/connectedhomeip/ Product