Impact
A null‑pointer dereference in the Matter SDK’s ReadRevision cause a device crash by sending a specially crafted read request. The fault occurs because the function does not validate the delegate pointer before dereferencing. Consequently, an unauthenticated attacker can trigger interrupting the operation of the affected device without compromising data confidentiality or integrity.
Affected Systems
Project Chip Matter SDK (connectedhomeip) distributed on GitHub. Versions released before 1.4.0 are vulnerable. The issue manifests in clusters that use the ReadRevisionAttribute function, and others.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity vulnerability. EPSS is listed as <1 %, signaling a low probability of existing exploits and the lack of current exploitation activity. The defect can be reached through an unauthenticated network request, meaning any device that accepts such traffic is at risk. Although the vulnerability is not listed in the CISA KEV catalog, its severity and remote reach warrant immediate attention.
OpenCVE Enrichment