CVE-2024-3454: CSA-IoT Matter

Low severity, CVSS 3.5. EPSS: 0.2% chance of exploitation in the next 30 days.

An implementation issue in the Connectivity Standards Alliance Matter 1.2 protocol as used in the connectedhomeip SDK allows a third party to disclose information about devices part of the same fabric (footprinting), even though the protocol is designed to prevent access to such information.

Affected products

  • CSA-IoT Matter: affected versions not specified

Published 2024-07-24. Last modified 2026-06-17.