Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m5xv-fggp-4j5r

Опубликовано: 08 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 9.5
CVSS3: 9.8

Описание

Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option.

This issue affects Advanced Software Framework: through 3.52.0.2574.

Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option.

This issue affects Advanced Software Framework: through 3.52.0.2574.

EPSS

Процентиль: 94%
0.11734
Средний

9.5 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software Framework: through 3.52.0.2574. ASF is no longer being supported. Apply provided workaround or migrate to an actively maintained framework.

EPSS

Процентиль: 94%
0.11734
Средний

9.5 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-120