Description Preview
Overview
The vulnerability affects Microchip's MiWi protocol, which is a wireless protocol designed for low-power applications in the sub-GHz frequency range. The Message Integrity Check (MIC) is a critical security feature designed to ensure data integrity and authenticity. By only validating half of the MIC bytes (2 out of 4), the implementation significantly weakens the cryptographic protection. This reduces the complexity for potential attackers to forge valid messages or manipulate communication within MiWi networks. The vulnerability impacts all versions of the MiWi software through version 6.5, affecting a wide range of devices and applications that rely on this protocol for secure communications.
Remediation
Users should update to the fixed versions of the Microchip Advanced Software Framework (ASF) that address this vulnerability. Microchip has released updates in ASF versions 3.50.0.100 and 3.51.0.101, as documented in their release notes. Organizations using MiWi in their products should:
- Upgrade to the latest version of the MiWi software that includes the fix
- Apply any available patches or updates from Microchip
- If immediate updates are not possible, consider implementing additional security measures at the network level to mitigate potential attacks
- Review system logs for any suspicious activities that might indicate exploitation of this vulnerability
- Contact Microchip support for product-specific guidance if needed
References
- Microchip ASF Release Notes 3.50.0.100: https://ww1.microchip.com/downloads/en/DeviceDoc/asf-release-notes-3.50.0.100-readme.pdf
- Microchip ASF Release Notes 3.51.0.101: https://ww1.microchip.com/downloads/en/DeviceDoc/asf-release-notes-3.51.0.101-readme.pdf
- Microchip Advanced Software Framework Downloads: https://www.microchip.com/en-us/development-tools-tools-and-software/libraries-code-examples-and-more/advanced-software-framework-for-sam-devices#Downloads
- MiWi Software Vulnerability Information: https://www.microchip.com/en-us/products/wireless-connectivity/software-vulnerability-response/miwi-software-vulnerability
- Microchip MiWi Protocol Information: https://www.microchip.com/en-us/products/wireless-connectivity/sub-ghz/miwi-protocol
- Microchip Product Change Notifications: https://www.microchip.com/product-change-notifications/#/
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- ConstructionConstruction
- Educational ServicesEducational Services
- Finance and InsuranceFinance and Insurance
- Health Care & Social AssistanceHealth Care & Social Assistance
- InformationInformation
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- ManufacturingManufacturing
- MiningMining
- Other Services (except Public Administration)Other Services (except Public Administration)
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Public AdministrationPublic Administration
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- Retail TradeRetail Trade
- Transportation & WarehousingTransportation & Warehousing
- UtilitiesUtilities
- Wholesale TradeWholesale Trade