# CVE-2024-29155

## Summary

- **CVE ID:** CVE-2024-29155
- **Severity:** MEDIUM
- **CVSS Score:** 4.3 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
- **CWE:** CWE-239
- **Published:** Oct 16, 2024
- **Last Modified:** Mar 13, 2026

## Description

On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is 
received, the device becomes incapable of completing the pairing 
process. A third party can inject a second PairReqNoInputNoOutput request 
just after a real one, causing the pair request to be blocked.

## Affected Products

- Microchip — RN4870 (0)

## References

- [CNA](https://www.microchip.com/en-us/product/rn4870)
- [CNA](https://ww1.microchip.com/downloads/aemDocuments/documents/WSG/ProductDocuments/SoftwareLibraries/Firmware/RN4870-71-Firmware-1.44.zip)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.23%
- **EPSS Percentile:** 14.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._