CVE-2025-56365
⚪ Do wiadomości
Błąd asercji w Matter SDK prowadzi do awarii aplikacji przy nieprawidłowym żądaniu.
CVSS
5.7
EPSS
0.6%
Exploit
poc
Vendor
csa-iot
Opis źródłowy (NVD)
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the code incorrectly treats the endpoint as valid due to missing checks in CodegenDataModelProvider::Invoke. This causes a VerifyOrDie failure in ProcessCommandDataIB and results in a crash (SIGABRT). The issue has been acknowledged and fixed in a later revision (PR #37207).
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.7 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.6% |
| Opublikowano (NVD) | 2026-07-14 23:17:27 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-05 19:36:22 UTC |
Referencje