Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software Framework: through 3.52.0.2574. ASF is no longer being supported. Apply provided workaround or migrate to an actively maintained framework.
History

Mon, 12 Aug 2024 15:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 08 Aug 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Microchip
Microchip advanced Software Framework
CPEs cpe:2.3:a:microchip:advanced_software_framework:*:*:*:*:*:*:*:*
Vendors & Products Microchip
Microchip advanced Software Framework
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Aug 2024 16:00:00 +0000

Type Values Removed Values Added
Description Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software Framework: through 3.52.0.2574. Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software Framework: through 3.52.0.2574. ASF is no longer being supported. Apply provided workaround or migrate to an actively maintained framework.

Thu, 08 Aug 2024 15:15:00 +0000

Type Values Removed Values Added
Description Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software Framework: through 3.52.0.2574.
Title Remote Code Execution in Advanced Software Framework DHCP server
Weaknesses CWE-120
CWE-20
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Microchip

Published: 2024-08-08T15:01:09.055Z

Updated: 2024-09-19T13:06:47.103Z

Reserved: 2024-08-05T14:10:12.165Z

Link: CVE-2024-7490

cve-icon Vulnrichment

Updated: 2024-09-19T13:06:47.103Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-08T15:15:19.057

Modified: 2024-08-12T15:22:20.267

Link: CVE-2024-7490

cve-icon Redhat

No data.