CVE-2025-56361
7.5Project Chip · Matter SDK (connectedhomeip)
A reachable assertion vulnerability in the Matter SDK allows unauthenticated attackers to cause a denial of service via a conflicting command sequence.
Executive summary
An unauthenticated remote denial of service vulnerability in the Project Chip Matter SDK allows attackers to crash affected devices by triggering a failed invariant check.
Vulnerability
A reachable assertion flaw exists in the Level Control cluster server tick logic, specifically triggered when a MoveToLevel command meets a conflicting write to the OperationMode attribute, requiring no authentication.
Business impact
A successful exploit results in a denial of service condition, forcing affected smart home and IoT devices to abort and crash. With a CVSS score of 7.5, the risk is classified as high because unauthenticated network attackers can disrupt critical device availability without requiring user interaction or prior access privileges.
Remediation
Immediate Action: Update the Matter SDK to the latest patched version provided by Project Chip or apply vendor-supplied patches as soon as they become available.
Proactive Monitoring: Monitor IoT network traffic for anomalous command sequences targeting the Level Control and Pump Configuration clusters.
Compensating Controls: Restrict network access to vulnerable smart home devices using strict firewall rules and network segmentation to prevent external exploitation.
Exploitation status
Public Exploit Available: No (active exploitation is unconfirmed, though CISA SSVC indicates a proof-of-concept exists).
Analyst recommendation
Given the high severity and potential for widespread service disruption across IoT deployments, organizations must prioritize tracking vendor updates. Apply the official patch immediately upon release to secure devices against denial of service attacks.