VDB
CVE-2024-7490
CVE-2024-7490
PUBLISHED
CVSS 9.5 CRITICAL
Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software Framework: through 3.52.0.2574.
EPSS 11.73% · 93.8th percentile
Risk Scores
CVSS 4.0
9.5
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS Score
11.73%
93.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microchip Techology | Advanced Software Framework | 0 |
| microchip | advanced_software_framework | 0 |
| microchip | advanced_software_framework | 0 |
Timeline
- Aug 8, 2024 CVE Published
- Aug 13, 2024 EPSS Score
- Sep 3, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Oct 14, 2024 EPSS Score
- Nov 4, 2024 EPSS Score
- Dec 17, 2024 EPSS Score
- Jan 7, 2025 EPSS Score
- Jan 28, 2025 EPSS Score
- Mar 10, 2025 EPSS Score
- Mar 17, 2025 EPSS Score
- Mar 20, 2025 EPSS Score