CVE-2025-56363
⚪ Do wiadomości
Dereferencja wskaźnika null w Matter SDK powoduje awarię urządzenia przy zdalnym ataku.
CVSS
5.7
EPSS
0.6%
Exploit
poc
Vendor
csa-iot
Opis źródłowy (NVD)
A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, TargetNavigator, etc.). The function lacks proper validation of the delegate pointer before dereferencing. A remote unauthenticated attacker can exploit this issue by sending a crafted read request, causing the device to crash (denial of service). This issue has been confirmed in SDK version v1.4 (commit ab3d5ae).
dos exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.7 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.6% |
| Opublikowano (NVD) | 2026-07-14 23:17:27 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-05 19:38:41 UTC |
Referencje
- https://github.com/project-chip/connectedhomeip/ ([email protected]) [Product]
- https://github.com/project-chip/connectedhomeip/issues/39173 ([email protected]) [Exploit, Issue Tracking]