Matter
This hub aggregates every CVE we track for Matter, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
11
CVEs tracked
1
Critical
8
High
0
In CISA KEV
Severity distribution
HIGH8LOW1MEDIUM1CRITICAL1
Monthly trend
0
0
0
0
3
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
5
2024-082026-07
Latest CVEs
The 11 most recently published vulnerabilities affecting Matter.
- CVE-2025-56362A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control cluster's periodic server tick logic. When a MoveToLevel command i...7.5
- CVE-2025-56364A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()` method is called without first checking whether a val...7.5
- CVE-2025-56363A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, Tar...7.5
- CVE-2025-56365A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent...7.5
- CVE-2025-56361A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server tick logic (`emberAfLevelControlClusterServerTick...7.5
- CVE-2026-20418In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction ...9.8
- CVE-2024-56318In raw\TCP.cpp in Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before 27ca6ec, there is a NULL pointer dereference in TCPBase::ProcessSingleMessage via TCP packets with zero message...7.5
- CVE-2024-56317In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes all existing ACL entries first, and then attempts to recreate them based on user input. If input valid...7.5
- CVE-2024-56319In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a denial of service (resource exhaustion).7.5
- CVE-2024-3297Session establishment lock-up during replay of CASE Sigma1 messages6.5
- CVE-2024-3454In-Fabric Matter Cluster Attribute Disclosure3.5
Product normalization is registry-driven with AI assist and human review. How it works