Записи Microchip
56 опубликованных записей вендора microchip.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 1,8 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 21,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-203 Observable Discrepancy2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
56 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
67На этой неделе | CVE-2022-40022Готовый эксплойт | Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.microchip · syncserver s650 firmware · CWE-77 | Критическая9,8 | — | 92,5 % | 13 февр. 2023 г. |
40В плане | CVE-2009-1608Proof of concept | Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrarmicrochip · mplab ide · CWE-119 | Критическая9,3 | — | 11,2 % | 11 мая 2009 г. |
40В плане | CVE-2024-22216Эксплойта нет | In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured formicrochip · maxview storage manager · CWE-284 | Критическая10,0 | — | 0,5 % | 8 янв. 2024 г. |
39Наблюдать | CVE-2024-9054Proof of concept | Remote code Execution inTimeProvider® 4100microchip · timeprovider 4100 firmware · CWE-78 | Высокая8,5 | — | 15,6 % | 4 окт. 2024 г. |
39Наблюдать | CVE-2023-51438Эксплойта нет | A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPCmicrochip · maxview storage manager · CWE-20 | Критическая9,8 | — | 0,6 % | 9 янв. 2024 г. |
38Наблюдать | CVE-2020-17441Эксплойта нет | An issue was discovered in picoTCP 1.7.0.altran · picotcp · CWE-125 | Критическая9,1 | — | 7,0 % | 11 дек. 2020 г. |
38Наблюдать | CVE-2009-1674Proof of concept | Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathmicrochip · mplab ide · CWE-119 | Критическая9,3 | — | 4,9 % | 18 мая 2009 г. |
38Наблюдать | CVE-2024-7490Эксплойта нет | Remote Code Execution in Advanced Software Framework DHCP servermicrochip · advanced software framework · CWE-120 | Критическая9,5 | — | 1,4 % | 8 авг. 2024 г. |
37Наблюдать | CVE-2019-16127Эксплойта нет | Atmel Advanced Software Framework (ASF) 4 has an Integer Overflow.microchip · advanced software framework 4 · CWE-190 | Критическая9,1 | — | 2,0 % | 22 окт. 2020 г. |
37Наблюдать | CVE-2026-2844Эксплойта нет | TimePictra Authentication Bypass Vulnerabilitymicrochip · timepictra · CWE-306 | Критическая9,3 | — | 0,4 % | 28 февр. 2026 г. |
37Наблюдать | CVE-2026-3010Эксплойта нет | TimePictra Stored Cross-Site Scriptingmicrochip · timepictra · CWE-79 | Критическая9,3 | — | 0,3 % | 28 февр. 2026 г. |
36Наблюдать | CVE-2020-27636Эксплойта нет | In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.microchip · mplab network creator · CWE-330 | Критическая9,1 | — | 0,9 % | 10 окт. 2023 г. |
35Наблюдать | CVE-2025-47900Эксплойта нет | RCE on backup configuration passwordmicrochip · timeprovider 4100 firmware · CWE-78 | Высокая8,9 | — | 1,4 % | 20 окт. 2025 г. |
35Наблюдать | CVE-2025-47901Эксплойта нет | RCE on restore configuration passwordmicrochip · timeprovider 4100 firmware · CWE-78 | Высокая8,9 | — | 1,4 % | 20 окт. 2025 г. |
34Наблюдать | CVE-2022-46403Эксплойта нет | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages.microchip · bm78 firmware · CWE-755 | Высокая8,6 | — | 0,9 % | 19 дек. 2022 г. |
34Наблюдать | CVE-2024-43685Эксплойта нет | Session token fixation in TimeProvider 4100microchip · timeprovider 4100 firmware · CWE-613 | Высокая8,7 | — | 0,4 % | 4 окт. 2024 г. |
34Наблюдать | CVE-2026-2336Эксплойта нет | Weak webstax_auth Cookie Authentication Allows Privilege Escalationmicrochip · istax · CWE-331 | Высокая8,7 | — | 0,2 % | 16 апр. 2026 г. |
34Наблюдать | CVE-2024-43683Эксплойта нет | Improper verification of the Host header in TimeProvider 4100microchip · timeprovider 4100 firmware · CWE-601 | Высокая8,7 | — | 0,2 % | 4 окт. 2024 г. |
34Наблюдать | CVE-2024-43684Эксплойта нет | Cross-Site Request Forgery vulnerability in TimeProvider 4100microchip · timeprovider 4100 firmware · CWE-79 | Высокая8,7 | — | 0,2 % | 4 окт. 2024 г. |
30Наблюдать | CVE-2020-12788Эксплойта нет | CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power analysis attacks.microchip · atsama5d21c-cu firmware · CWE-203 | Высокая7,5 | — | 1,3 % | 14 сент. 2020 г. |
30Наблюдать | CVE-2021-37605Эксплойта нет | In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Mesmicrochip · miwi · CWE-670 | Высокая7,5 | — | 1,3 % | 5 авг. 2021 г. |
30Наблюдать | CVE-2020-12789Эксплойта нет | The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.microchip · atsama5d21c-cu firmware · CWE-798 | Высокая7,5 | — | 1,2 % | 14 сент. 2020 г. |
30Наблюдать | CVE-2020-12787Эксплойта нет | Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling.microchip · atsama5d21c-cu firmware | Высокая7,5 | — | 1,2 % | 14 сент. 2020 г. |
30Наблюдать | CVE-2021-37604Эксплойта нет | In version 6.5 of Microchip MiWi software and all previous versions including legacy products, there is a possibility of frame counters beinmicrochip · miwi · CWE-670 | Высокая7,5 | — | 1,2 % | 5 авг. 2021 г. |
30Наблюдать | CVE-2020-9034Эксплойта нет | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to umicrochip · syncserver s100 firmware | Высокая7,5 | — | 0,9 % | 16 февр. 2020 г. |
- CVE-2022-4002267На этой неделе
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
КритическаяCVSS 9,8Готовый эксплойтEPSS 92 %microchip · syncserver s650 firmware13 февр. 2023 г.
- CVE-2009-160840В плане
Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrar
КритическаяCVSS 9,3Proof of conceptEPSS 11 %microchip · mplab ide11 мая 2009 г.
- CVE-2024-2221640В плане
In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %microchip · maxview storage manager8 янв. 2024 г.
- CVE-2024-905439Наблюдать
Remote code Execution inTimeProvider® 4100
ВысокаяCVSS 8,5Proof of conceptEPSS 16 %microchip · timeprovider 4100 firmware4 окт. 2024 г.
- CVE-2023-5143839Наблюдать
A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %microchip · maxview storage manager9 янв. 2024 г.
- CVE-2020-1744138Наблюдать
An issue was discovered in picoTCP 1.7.0.
КритическаяCVSS 9,1Эксплойта нетEPSS 7 %altran · picotcp11 дек. 2020 г.
- CVE-2009-167438Наблюдать
Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof path
КритическаяCVSS 9,3Proof of conceptEPSS 5 %microchip · mplab ide18 мая 2009 г.
- CVE-2024-749038Наблюдать
Remote Code Execution in Advanced Software Framework DHCP server
КритическаяCVSS 9,5Эксплойта нетEPSS 1 %microchip · advanced software framework8 авг. 2024 г.
- CVE-2019-1612737Наблюдать
Atmel Advanced Software Framework (ASF) 4 has an Integer Overflow.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %microchip · advanced software framework 422 окт. 2020 г.
- CVE-2026-284437Наблюдать
TimePictra Authentication Bypass Vulnerability
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %microchip · timepictra28 февр. 2026 г.
- CVE-2026-301037Наблюдать
TimePictra Stored Cross-Site Scripting
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %microchip · timepictra28 февр. 2026 г.
- CVE-2020-2763636Наблюдать
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %microchip · mplab network creator10 окт. 2023 г.
- CVE-2025-4790035Наблюдать
RCE on backup configuration password
ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %microchip · timeprovider 4100 firmware20 окт. 2025 г.
- CVE-2025-4790135Наблюдать
RCE on restore configuration password
ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %microchip · timeprovider 4100 firmware20 окт. 2025 г.
- CVE-2022-4640334Наблюдать
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %microchip · bm78 firmware19 дек. 2022 г.
- CVE-2024-4368534Наблюдать
Session token fixation in TimeProvider 4100
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %microchip · timeprovider 4100 firmware4 окт. 2024 г.
- CVE-2026-233634Наблюдать
Weak webstax_auth Cookie Authentication Allows Privilege Escalation
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %microchip · istax16 апр. 2026 г.
- CVE-2024-4368334Наблюдать
Improper verification of the Host header in TimeProvider 4100
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %microchip · timeprovider 4100 firmware4 окт. 2024 г.
- CVE-2024-4368434Наблюдать
Cross-Site Request Forgery vulnerability in TimeProvider 4100
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %microchip · timeprovider 4100 firmware4 окт. 2024 г.
- CVE-2020-1278830Наблюдать
CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power analysis attacks.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %microchip · atsama5d21c-cu firmware14 сент. 2020 г.
- CVE-2021-3760530Наблюдать
In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Mes
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %microchip · miwi5 авг. 2021 г.
- CVE-2020-1278930Наблюдать
The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %microchip · atsama5d21c-cu firmware14 сент. 2020 г.
- CVE-2020-1278730Наблюдать
Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %microchip · atsama5d21c-cu firmware14 сент. 2020 г.
- CVE-2021-3760430Наблюдать
In version 6.5 of Microchip MiWi software and all previous versions including legacy products, there is a possibility of frame counters bein
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %microchip · miwi5 авг. 2021 г.
- CVE-2020-903430Наблюдать
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to u
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %microchip · syncserver s100 firmware16 февр. 2020 г.