CVE-2024-3297

An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between two devices, as implemented in the Matter protocol versions before Matter 1.1 allows an attacker to replay manipulated CASE Sigma1 messages to make the device unresponsive until the device is power-cycled.
Configurations

Configuration 1 (hide)

cpe:2.3:a:csa-iot:matter:-:*:*:*:*:*:*:*

History

10 Sep 2024, 15:41

Type Values Removed Values Added
First Time Csa-iot
Csa-iot matter
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:csa-iot:matter:-:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://www.bitdefender.com/support/security-advisories/session-establishment-lock-up-during-replay-of-case-sigma1-messages/ - () https://www.bitdefender.com/support/security-advisories/session-establishment-lock-up-during-replay-of-case-sigma1-messages/ - Third Party Advisory

24 Jul 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-24 08:15

Updated : 2024-09-10 15:41


NVD link : CVE-2024-3297

Mitre link : CVE-2024-3297


JSON object : View

Products Affected

csa-iot

  • matter