Matter SDK
cpe:2.3:a:csa-iot:matter:*:*:*:*:*:*:*
- < 1.4.0
A reachable assertion vulnerability has been identified in the Matter SDK (connectedhomeip) versions prior to 1.4.0. The issue arises in the interaction model command processing logic, where an InvokeCommandRequest sent to a nonexistent endpoint and cluster is incorrectly validated. This flaw, due to missing checks, leads to a VerifyOrDie failure in ProcessCommandDataIB, causing a crash (SIGABRT). The vulnerability has been acknowledged and fixed in a later revision (PR #37207).
Exploitation of this vulnerability causes a crash due to a failed assertion, disrupting the application's normal operation.
The vulnerability can be reproduced by sending an InvokeCommandRequest to a nonexistent endpoint (0x34) and cluster (0x34). The all-cluster-app application will incorrectly respond with a success status instead of an 'Endpoint Not Found' error. This issue can be replicated using the chip-tool command-line tool.
Users can update to Matter SDK version 1.4.2.0 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.