A critical vulnerability in Microchip's Advanced Software Framework (ASF) could allow remote code execution on vulnerable systems.

The vulnerability is tracked as CVE-2024-7490 and has received a CVSS score of 9.5/10. It has been classified as a “stack-based overflow vulnerability”.
See also: Ivanti warns of new CSA vulnerability
" A vulnerability exists in all publicly available examples of the ASF codebase that allows a specially crafted DHCP request to cause a stack-based overflow that could lead to remote code execution ," the CERT Coordination Center (CERT/CC) said
CERT/CC warns of the risk of the vulnerability given that the software is no longer supported and can affect IoT devices.
The vulnerability affects ASF 3.52.0.2574 and all previous versions of Microchip ASF. Additionally, CERT/CC reported that multiple forks of the tinydhcp software may also be affected by the bug.
See also: PoC exploit for critical Google Chrome vulnerability
Currently, there are no fixes to address the CVE-2024-7490 vulnerability, other than replacing the service with another one.

The impact of an attack through this vulnerability could be devastating, especially in environments where Microchip ASF is used in critical infrastructure or embedded systems that control essential functions.
General protection methods
To mitigate the risk of such vulnerabilities, users and organizations should update software their to the latest version. Additionally, implementing strong security measures, such as network segmentation and systems intrusion detection, can help protect against potential exploitation.
See also: Atlassian patches multiple high-severity vulnerabilities
Additionally, regular security audits and penetration tests can help identify any potential system vulnerabilities and allow for proactive remediation before malicious actors can exploit them. It is important for organizations to prioritize security and constantly monitor their systems for any signs of suspicious activity.
As technology advances, so do the methods used by cybercriminals to exploit vulnerabilities and gain unauthorized access to systems. Therefore, vigilance is vital to maintaining a secure environment.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
