Back to Database
Status published
High
CVE-2021-37605
In version 6.5 Microchip MiWi software and all previous versions...
Vulnerability Description
In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Message Integrity Check (MIC) bytes.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-37605
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.microchip.com/product-change-notifications/#/
- https://www.microchip.com/en-us/products/wireless-connectivity/sub-ghz/miwi-protocol
- https://ww1.microchip.com/downloads/en/DeviceDoc/asf-release-notes-3.50.0.100-readme.pdf
- https://www.microchip.com/en-us/development-tools-tools-and-software/libraries-code-examples-and-more/advanced-software-framework-for-sam-devices#Downloads
- https://ww1.microchip.com/downloads/en/DeviceDoc/asf-release-notes-3.51.0.101-readme.pdf
- https://www.microchip.com/en-us/products/wireless-connectivity/software-vulnerability-response/miwi-software-vulnerability
More from microchip
View All →CVE-2022-46403
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC...
Unknown
0
CVE-2022-46402
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC...
Unknown
0
CVE-2022-46401
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC...
Unknown
0
CVE-2022-46400
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC...
Unknown
0
CVE-2022-46399
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC...
Unknown
0
Affected Vendor
microchip
View all reports →Affected Software
miwi
Vulnerable Versions:
6.5
Timeline
Official Publish:
August 5th, 2021
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.