CVE-2025-56363

⚪ Do wiadomości

Dereferencja wskaźnika null w Matter SDK powoduje awarię urządzenia przy zdalnym ataku.

CVSS
5.7
EPSS
0.6%
Exploit
poc
Vendor
csa-iot
Opis źródłowy (NVD)

A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, TargetNavigator, etc.). The function lacks proper validation of the delegate pointer before dereferencing. A remote unauthenticated attacker can exploit this issue by sending a crafted read request, causing the device to crash (denial of service). This issue has been confirmed in SDK version v1.4 (commit ab3d5ae).

dos exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.7
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.6%
Opublikowano (NVD)2026-07-14 23:17:27 UTC
Ostatnia modyfikacja (NVD)2026-10-05 19:38:41 UTC
Referencje