The following issues affect version 6.5 of MiWi software:
In the code snippet below, the frame counters were validated/considered before the payload authentication.
In version 6.5 of our MiWi software and all previous versions including legacy products, the stack is validating only two out of four Message Integrity Check (MIC) bytes.
In the code snippet below, only two out of four MIC bytes were used.
Special thanks to Szymon Heidrich of Carrier Global Corporation for reporting this vulnerability.