HomeSecurityCritical vulnerability in Microchip ASF puts IoT devices at risk

Critical vulnerability in Microchip ASF puts IoT devices at risk

A critical vulnerability in Microchip's Advanced Software Framework (ASF) could allow remote code execution on vulnerable systems.

Microchip ASF Advanced Software Framework vulnerability

The vulnerability is tracked as CVE-2024-7490 and has received a CVSS score of 9.5/10. It has been classified as a “stack-based overflow vulnerability”.

See also: Ivanti warns of new CSA vulnerability

" A vulnerability exists in all publicly available examples of the ASF codebase that allows a specially crafted DHCP request to cause a stack-based overflow that could lead to remote code execution ," the CERT Coordination Center (CERT/CC) said

CERT/CC warns of the risk of the vulnerability given that the software is no longer supported and can affect IoT devices.

The vulnerability affects ASF 3.52.0.2574 and all previous versions of Microchip ASF. Additionally, CERT/CC reported that multiple forks of the tinydhcp software may also be affected by the bug.

See also: PoC exploit for critical Google Chrome vulnerability

Currently, there are no fixes to address the CVE-2024-7490 vulnerability, other than replacing the service with another one.

Critical vulnerability in Microchip ASF puts IoT devices at risk

The impact of an attack through this vulnerability could be devastating, especially in environments where Microchip ASF is used in critical infrastructure or embedded systems that control essential functions.

General protection methods

To mitigate the risk of such vulnerabilities, users and organizations should update software their to the latest version. Additionally, implementing strong security measures, such as network segmentation and systems intrusion detection, can help protect against potential exploitation.

See also: Atlassian patches multiple high-severity vulnerabilities

Additionally, regular security audits and penetration tests can help identify any potential system vulnerabilities and allow for proactive remediation before malicious actors can exploit them. It is important for organizations to prioritize security and constantly monitor their systems for any signs of suspicious activity.

As technology advances, so do the methods used by cybercriminals to exploit vulnerabilities and gain unauthorized access to systems. Therefore, vigilance is vital to maintaining a secure environment.

Source: thehackernews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS