Microchip records
56 published records for vendor microchip.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 1.8%
- Pre-auth RCE
- 4
- With a fix record
- 21.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-203 Observable Discrepancy2
The weakness classes this vendor ships most often: where to look.
CWEAll records
56 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
67This week | CVE-2022-40022Weaponized | Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.microchip · syncserver s650 firmware · CWE-77 | Critical9.8 | — | 92.5% | Feb 13, 2023 |
40Plan | CVE-2009-1608Proof of concept | Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrarmicrochip · mplab ide · CWE-119 | Critical9.3 | — | 11.2% | May 11, 2009 |
40Plan | CVE-2024-22216No exploit | In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured formicrochip · maxview storage manager · CWE-284 | Critical10.0 | — | 0.5% | Jan 8, 2024 |
39Monitor | CVE-2024-9054Proof of concept | Remote code Execution inTimeProvider® 4100microchip · timeprovider 4100 firmware · CWE-78 | High8.5 | — | 15.6% | Oct 4, 2024 |
39Monitor | CVE-2023-51438No exploit | A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPCmicrochip · maxview storage manager · CWE-20 | Critical9.8 | — | 0.6% | Jan 9, 2024 |
38Monitor | CVE-2020-17441No exploit | An issue was discovered in picoTCP 1.7.0.altran · picotcp · CWE-125 | Critical9.1 | — | 7.0% | Dec 11, 2020 |
38Monitor | CVE-2009-1674Proof of concept | Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathmicrochip · mplab ide · CWE-119 | Critical9.3 | — | 4.9% | May 18, 2009 |
38Monitor | CVE-2024-7490No exploit | Remote Code Execution in Advanced Software Framework DHCP servermicrochip · advanced software framework · CWE-120 | Critical9.5 | — | 1.4% | Aug 8, 2024 |
37Monitor | CVE-2019-16127No exploit | Atmel Advanced Software Framework (ASF) 4 has an Integer Overflow.microchip · advanced software framework 4 · CWE-190 | Critical9.1 | — | 2.0% | Oct 22, 2020 |
37Monitor | CVE-2026-2844No exploit | TimePictra Authentication Bypass Vulnerabilitymicrochip · timepictra · CWE-306 | Critical9.3 | — | 0.4% | Feb 28, 2026 |
37Monitor | CVE-2026-3010No exploit | TimePictra Stored Cross-Site Scriptingmicrochip · timepictra · CWE-79 | Critical9.3 | — | 0.3% | Feb 28, 2026 |
36Monitor | CVE-2020-27636No exploit | In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.microchip · mplab network creator · CWE-330 | Critical9.1 | — | 0.9% | Oct 10, 2023 |
35Monitor | CVE-2025-47900No exploit | RCE on backup configuration passwordmicrochip · timeprovider 4100 firmware · CWE-78 | High8.9 | — | 1.4% | Oct 20, 2025 |
35Monitor | CVE-2025-47901No exploit | RCE on restore configuration passwordmicrochip · timeprovider 4100 firmware · CWE-78 | High8.9 | — | 1.4% | Oct 20, 2025 |
34Monitor | CVE-2022-46403No exploit | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages.microchip · bm78 firmware · CWE-755 | High8.6 | — | 0.9% | Dec 19, 2022 |
34Monitor | CVE-2024-43685No exploit | Session token fixation in TimeProvider 4100microchip · timeprovider 4100 firmware · CWE-613 | High8.7 | — | 0.4% | Oct 4, 2024 |
34Monitor | CVE-2026-2336No exploit | Weak webstax_auth Cookie Authentication Allows Privilege Escalationmicrochip · istax · CWE-331 | High8.7 | — | 0.2% | Apr 16, 2026 |
34Monitor | CVE-2024-43683No exploit | Improper verification of the Host header in TimeProvider 4100microchip · timeprovider 4100 firmware · CWE-601 | High8.7 | — | 0.2% | Oct 4, 2024 |
34Monitor | CVE-2024-43684No exploit | Cross-Site Request Forgery vulnerability in TimeProvider 4100microchip · timeprovider 4100 firmware · CWE-79 | High8.7 | — | 0.2% | Oct 4, 2024 |
30Monitor | CVE-2020-12788No exploit | CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power analysis attacks.microchip · atsama5d21c-cu firmware · CWE-203 | High7.5 | — | 1.3% | Sep 14, 2020 |
30Monitor | CVE-2021-37605No exploit | In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Mesmicrochip · miwi · CWE-670 | High7.5 | — | 1.3% | Aug 5, 2021 |
30Monitor | CVE-2020-12789No exploit | The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.microchip · atsama5d21c-cu firmware · CWE-798 | High7.5 | — | 1.2% | Sep 14, 2020 |
30Monitor | CVE-2020-12787No exploit | Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling.microchip · atsama5d21c-cu firmware | High7.5 | — | 1.2% | Sep 14, 2020 |
30Monitor | CVE-2021-37604No exploit | In version 6.5 of Microchip MiWi software and all previous versions including legacy products, there is a possibility of frame counters beinmicrochip · miwi · CWE-670 | High7.5 | — | 1.2% | Aug 5, 2021 |
30Monitor | CVE-2020-9034No exploit | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to umicrochip · syncserver s100 firmware | High7.5 | — | 0.9% | Feb 16, 2020 |
- CVE-2022-4002267This week
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
CriticalCVSS 9.8WeaponizedEPSS 92%microchip · syncserver s650 firmwareFeb 13, 2023
- CVE-2009-160840Plan
Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrar
CriticalCVSS 9.3Proof of conceptEPSS 11%microchip · mplab ideMay 11, 2009
- CVE-2024-2221640Plan
In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for
CriticalCVSS 10.0No exploitEPSS 1%microchip · maxview storage managerJan 8, 2024
- CVE-2024-905439Monitor
Remote code Execution inTimeProvider® 4100
HighCVSS 8.5Proof of conceptEPSS 16%microchip · timeprovider 4100 firmwareOct 4, 2024
- CVE-2023-5143839Monitor
A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC
CriticalCVSS 9.8No exploitEPSS 1%microchip · maxview storage managerJan 9, 2024
- CVE-2020-1744138Monitor
An issue was discovered in picoTCP 1.7.0.
CriticalCVSS 9.1No exploitEPSS 7%altran · picotcpDec 11, 2020
- CVE-2009-167438Monitor
Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof path
CriticalCVSS 9.3Proof of conceptEPSS 5%microchip · mplab ideMay 18, 2009
- CVE-2024-749038Monitor
Remote Code Execution in Advanced Software Framework DHCP server
CriticalCVSS 9.5No exploitEPSS 1%microchip · advanced software frameworkAug 8, 2024
- CVE-2019-1612737Monitor
Atmel Advanced Software Framework (ASF) 4 has an Integer Overflow.
CriticalCVSS 9.1No exploitEPSS 2%microchip · advanced software framework 4Oct 22, 2020
- CVE-2026-284437Monitor
TimePictra Authentication Bypass Vulnerability
CriticalCVSS 9.3No exploitEPSS 0%microchip · timepictraFeb 28, 2026
- CVE-2026-301037Monitor
TimePictra Stored Cross-Site Scripting
CriticalCVSS 9.3No exploitEPSS 0%microchip · timepictraFeb 28, 2026
- CVE-2020-2763636Monitor
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
CriticalCVSS 9.1No exploitEPSS 1%microchip · mplab network creatorOct 10, 2023
- CVE-2025-4790035Monitor
RCE on backup configuration password
HighCVSS 8.9No exploitEPSS 1%microchip · timeprovider 4100 firmwareOct 20, 2025
- CVE-2025-4790135Monitor
RCE on restore configuration password
HighCVSS 8.9No exploitEPSS 1%microchip · timeprovider 4100 firmwareOct 20, 2025
- CVE-2022-4640334Monitor
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages.
HighCVSS 8.6No exploitEPSS 1%microchip · bm78 firmwareDec 19, 2022
- CVE-2024-4368534Monitor
Session token fixation in TimeProvider 4100
HighCVSS 8.7No exploitEPSS 0%microchip · timeprovider 4100 firmwareOct 4, 2024
- CVE-2026-233634Monitor
Weak webstax_auth Cookie Authentication Allows Privilege Escalation
HighCVSS 8.7No exploitEPSS 0%microchip · istaxApr 16, 2026
- CVE-2024-4368334Monitor
Improper verification of the Host header in TimeProvider 4100
HighCVSS 8.7No exploitEPSS 0%microchip · timeprovider 4100 firmwareOct 4, 2024
- CVE-2024-4368434Monitor
Cross-Site Request Forgery vulnerability in TimeProvider 4100
HighCVSS 8.7No exploitEPSS 0%microchip · timeprovider 4100 firmwareOct 4, 2024
- CVE-2020-1278830Monitor
CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power analysis attacks.
HighCVSS 7.5No exploitEPSS 1%microchip · atsama5d21c-cu firmwareSep 14, 2020
- CVE-2021-3760530Monitor
In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Mes
HighCVSS 7.5No exploitEPSS 1%microchip · miwiAug 5, 2021
- CVE-2020-1278930Monitor
The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.
HighCVSS 7.5No exploitEPSS 1%microchip · atsama5d21c-cu firmwareSep 14, 2020
- CVE-2020-1278730Monitor
Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling.
HighCVSS 7.5No exploitEPSS 1%microchip · atsama5d21c-cu firmwareSep 14, 2020
- CVE-2021-3760430Monitor
In version 6.5 of Microchip MiWi software and all previous versions including legacy products, there is a possibility of frame counters bein
HighCVSS 7.5No exploitEPSS 1%microchip · miwiAug 5, 2021
- CVE-2020-903430Monitor
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to u
HighCVSS 7.5No exploitEPSS 1%microchip · syncserver s100 firmwareFeb 16, 2020