CVE-2025-56362

⚪ Do wiadomości

Wykrycie asercji w Matter SDK umożliwia zdalne wywołanie awarii serwera.

CVSS
5.7
EPSS
0.6%
Exploit
poc
Vendor
csa-iot
Opis źródłowy (NVD)

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control cluster's periodic server tick logic. When a MoveToLevel command is sent and immediately followed by a write of OperationMode=2 (in the Pump Configuration and Control cluster), the server tick function violates the assertion `currentLevel < maxLevel`, resulting in a crash. This can be exploited remotely without authentication to cause denial of service. Affected versions include 1.3 and 1.4 (commit ab3d5ae).

dos exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.7
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.6%
Opublikowano (NVD)2026-07-14 23:17:27 UTC
Ostatnia modyfikacja (NVD)2026-10-05 19:38:18 UTC
Referencje