CRITICAL🇵🇱 Wersja polska

CVE-2024-7490

CVSS 9.5v4.0pub. 2024-08-08upd. 2025-09-29

Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software Framework: through 3.52.0.2574. ASF is no longer being supported. Apply provided workaround or migrate to an actively maintained framework.

🤖 AI Analysis
How it works

The vulnerability results from improper input validation (CWE-120 — classic buffer overflow) in the tinydhcpserver.C files and the lwip_dhcp_find_option function. An attacker can remotely, without authentication, send crafted DHCP packets that cause a buffer overflow in the vulnerable DHCP option handling routine. The buffer overflow allows overwriting memory areas and hijacking program execution flow control.

Impact

An attacker can gain the ability to execute arbitrary remote code (RCE) on a device running the vulnerable DHCP server, which may lead to complete system takeover and pose a threat to dependent environments.

Mitigation & patch

The manufacturer does not plan to release a patch — Microchip Advanced Software Framework is no longer actively developed. Available workarounds indicated by the manufacturer should be applied, or migration to an actively maintained framework should be performed as soon as possible. Workaround details are available at: https://www.kb.cert.org/vuls/id/138043

Who is affected

Microchip Advanced Software Framework in all versions up to and including 3.52.0.2574, using the sample DHCP server (files tinydhcpserver.C, function lwip_dhcp_find_option).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Microchip Advanced Software Framework

    APP
    Microchip
    ≤ 3.52.0.2574
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2026-3010CRITICAL9.3PL ✓same vendor

XSS w Microchip TimePictra – wstrzyknięcie złośliwego skryptu

CVE-2026-2844CRITICAL9.3PL ✓same vendor

Brak uwierzytelnienia dla funkcji krytycznych w Microchip TimePictra

CVE-2023-51438CRITICAL10.0PL ✓same vendor

Nieautoryzowany dostęp w maxView Storage Manager via Redfish Server

CVE-2024-22216CRITICAL10.0PL ✓same vendor

Nieautoryzowany dostęp w Microchip maxView Storage Manager przez serwer Redfish

CVE-2020-27636CRITICAL9.1PL ✓same vendor

Microchip MPLAB Net — słaba losowość numerów sekwencyjnych TCP (ISN)