We detect you are using an unsupported browser. For the best experience, please visit the site using Chrome, Firefox, Safari, or Edge. X
Maximize Your Experience: Reap the Personalized Advantages by Completing Your Profile to Its Fullest. Update Here
Stay in the loop with the latest from Microchip. Update your profile while you are at it. Update Here
Complete your profile to access more resources. Update Here

MiWi™ Software Vulnerability

Vulnerabilities Covered


This page addresses the following vulnerabilities identified by Common Vulnerabilities and Exposures (CVEs):

  • CVE-2021-37604: A message-processing vulnerability that may allow an attacker to manipulate frame counter handling before message authentication is completed, potentially leading to denial-of-service conditions or reduced protection against replay attacks
  • CVE-2021-37605: A message-authentication vulnerability where only a subset of Message Integrity Check (MIC) bytes is validated, potentially reducing the effectiveness of message authentication protections

Affected Products and Resolution


Software/FirmwareAssociated HardwareCVEResolution/Mitigation
MiWi™ Software 6.5 and earlierAny hardware running affected software versions

CVE-2021-37604

CVE-2021-37605

Update to version 6.6 or later

Products Not Listed


Only products listed in the Affected Products and Resolution section of this advisory are known to be affected by these vulnerabilities.

Credits


Special thanks to Szymon Heidrich of Carrier Global Corporation for reporting this vulnerability.

Live Chat

Need Help?

Privacy Policy