CVE-2025-56365

⚪ Do wiadomości

Błąd asercji w Matter SDK prowadzi do awarii aplikacji przy nieprawidłowym żądaniu.

CVSS
5.7
EPSS
0.6%
Exploit
poc
Vendor
csa-iot
Opis źródłowy (NVD)

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the code incorrectly treats the endpoint as valid due to missing checks in CodegenDataModelProvider::Invoke. This causes a VerifyOrDie failure in ProcessCommandDataIB and results in a crash (SIGABRT). The issue has been acknowledged and fixed in a later revision (PR #37207).

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.7
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.6%
Opublikowano (NVD)2026-07-14 23:17:27 UTC
Ostatnia modyfikacja (NVD)2026-10-05 19:36:22 UTC
Referencje