CVE-2024-3297

An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between two devices, as implemented in the Matter protocol versions before Matter 1.1 allows an attacker to replay manipulated CASE Sigma1 messages to make the device unresponsive until the device is power-cycled.
Configurations

Configuration 1 (hide)

cpe:2.3:a:csa-iot:matter:-:*:*:*:*:*:*:*

History

21 Nov 2024, 09:29

Type Values Removed Values Added
References () https://www.bitdefender.com/support/security-advisories/session-establishment-lock-up-during-replay-of-case-sigma1-messages/ - Third Party Advisory () https://www.bitdefender.com/support/security-advisories/session-establishment-lock-up-during-replay-of-case-sigma1-messages/ - Third Party Advisory

10 Sep 2024, 15:41

Type Values Removed Values Added
First Time Csa-iot matter
Csa-iot
References () https://www.bitdefender.com/support/security-advisories/session-establishment-lock-up-during-replay-of-case-sigma1-messages/ - () https://www.bitdefender.com/support/security-advisories/session-establishment-lock-up-during-replay-of-case-sigma1-messages/ - Third Party Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:csa-iot:matter:-:*:*:*:*:*:*:*

24 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) Un problema en el protocolo de establecimiento de sesión autenticado por certificado (CASE) para establecer sesiones seguras entre dos dispositivos, tal como se implementó en las versiones del protocolo Matter anteriores a Matter 1.1, permite a un atacante reproducir mensajes CASE Sigma1 manipulados para que el dispositivo no responda hasta que se encienda ciclado.

24 Jul 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-24 08:15

Updated : 2024-11-21 09:29


NVD link : CVE-2024-3297

Mitre link : CVE-2024-3297

CVE.ORG link : CVE-2024-3297


JSON object : View

Products Affected

csa-iot

  • matter
CWE
CWE-400

Uncontrolled Resource Consumption

NVD-CWE-noinfo