Tag: Microchip ASF

Critical Flaw in Microchip ASF Exposes IoT Devices to Remote Code Execution Risk
News

Critical Flaw in Microchip ASF Exposes IoT Devices to Remote Code Execution Risk

The Microchip Advanced Software Framework (ASF) includes a serious security vulnerability that, if successfully exploited, might result in remote code execution. The vulnerability has a CVSS score of 9.5 out of a possible 10.0, and it is tagged as CVE-2024-7490. It has been defined as a stack-based overflow vulnerability resulting from insufficient input validation in ASF's tinydhcp server implementation. The CERT Coordination Center (CERT/CC) released an alert stating that there is a vulnerability in all publicly accessible samples of the ASF codebase that permits a specially designed DHCP request to create a stack-based overflow that could result in remote code execution read more about Critical Flaw in Microchip ASF Exposes IoT Devices to Remote Code Execution Risk. Get up to ...