Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software Framework: through 3.52.0.2574. ASF is no longer being supported. Apply provided workaround or migrate to an actively maintained framework.
The vulnerability results from improper input validation (CWE-120 — classic buffer overflow) in the tinydhcpserver.C files and the lwip_dhcp_find_option function. An attacker can remotely, without authentication, send crafted DHCP packets that cause a buffer overflow in the vulnerable DHCP option handling routine. The buffer overflow allows overwriting memory areas and hijacking program execution flow control.
An attacker can gain the ability to execute arbitrary remote code (RCE) on a device running the vulnerable DHCP server, which may lead to complete system takeover and pose a threat to dependent environments.
The manufacturer does not plan to release a patch — Microchip Advanced Software Framework is no longer actively developed. Available workarounds indicated by the manufacturer should be applied, or migration to an actively maintained framework should be performed as soon as possible. Workaround details are available at: https://www.kb.cert.org/vuls/id/138043
Microchip Advanced Software Framework in all versions up to and including 3.52.0.2574, using the sample DHCP server (files tinydhcpserver.C, function lwip_dhcp_find_option).
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMicrochip Advanced Software Framework
APPMicrochip≤ 3.52.0.2574
Related vulnerabilities
XSS w Microchip TimePictra – wstrzyknięcie złośliwego skryptu
Brak uwierzytelnienia dla funkcji krytycznych w Microchip TimePictra
Nieautoryzowany dostęp w maxView Storage Manager via Redfish Server
Nieautoryzowany dostęp w Microchip maxView Storage Manager przez serwer Redfish
Microchip MPLAB Net — słaba losowość numerów sekwencyjnych TCP (ISN)