Microchip kayıtları
microchip üreticisine ait 56 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %1,8
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %21,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-203 Observable Discrepancy2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
56 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
67Bu hafta | CVE-2022-40022Silahlaştırılmış | Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.microchip · syncserver s650 firmware · CWE-77 | Kritik9,8 | — | %92,5 | 13 Şub 2023 |
40Planlayın | CVE-2009-1608Kavram kanıtı | Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrarmicrochip · mplab ide · CWE-119 | Kritik9,3 | — | %11,2 | 11 May 2009 |
40Planlayın | CVE-2024-22216İstismar yok | In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured formicrochip · maxview storage manager · CWE-284 | Kritik10,0 | — | %0,5 | 8 Oca 2024 |
39İzleyin | CVE-2024-9054Kavram kanıtı | Remote code Execution inTimeProvider® 4100microchip · timeprovider 4100 firmware · CWE-78 | Yüksek8,5 | — | %15,6 | 4 Eki 2024 |
39İzleyin | CVE-2023-51438İstismar yok | A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPCmicrochip · maxview storage manager · CWE-20 | Kritik9,8 | — | %0,6 | 9 Oca 2024 |
38İzleyin | CVE-2020-17441İstismar yok | An issue was discovered in picoTCP 1.7.0.altran · picotcp · CWE-125 | Kritik9,1 | — | %7,0 | 11 Ara 2020 |
38İzleyin | CVE-2009-1674Kavram kanıtı | Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathmicrochip · mplab ide · CWE-119 | Kritik9,3 | — | %4,9 | 18 May 2009 |
38İzleyin | CVE-2024-7490İstismar yok | Remote Code Execution in Advanced Software Framework DHCP servermicrochip · advanced software framework · CWE-120 | Kritik9,5 | — | %1,4 | 8 Ağu 2024 |
37İzleyin | CVE-2019-16127İstismar yok | Atmel Advanced Software Framework (ASF) 4 has an Integer Overflow.microchip · advanced software framework 4 · CWE-190 | Kritik9,1 | — | %2,0 | 22 Eki 2020 |
37İzleyin | CVE-2026-2844İstismar yok | TimePictra Authentication Bypass Vulnerabilitymicrochip · timepictra · CWE-306 | Kritik9,3 | — | %0,4 | 28 Şub 2026 |
37İzleyin | CVE-2026-3010İstismar yok | TimePictra Stored Cross-Site Scriptingmicrochip · timepictra · CWE-79 | Kritik9,3 | — | %0,3 | 28 Şub 2026 |
36İzleyin | CVE-2020-27636İstismar yok | In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.microchip · mplab network creator · CWE-330 | Kritik9,1 | — | %0,9 | 10 Eki 2023 |
35İzleyin | CVE-2025-47900İstismar yok | RCE on backup configuration passwordmicrochip · timeprovider 4100 firmware · CWE-78 | Yüksek8,9 | — | %1,4 | 20 Eki 2025 |
35İzleyin | CVE-2025-47901İstismar yok | RCE on restore configuration passwordmicrochip · timeprovider 4100 firmware · CWE-78 | Yüksek8,9 | — | %1,4 | 20 Eki 2025 |
34İzleyin | CVE-2022-46403İstismar yok | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages.microchip · bm78 firmware · CWE-755 | Yüksek8,6 | — | %0,8 | 19 Ara 2022 |
34İzleyin | CVE-2024-43685İstismar yok | Session token fixation in TimeProvider 4100microchip · timeprovider 4100 firmware · CWE-613 | Yüksek8,7 | — | %0,4 | 4 Eki 2024 |
34İzleyin | CVE-2026-2336İstismar yok | Weak webstax_auth Cookie Authentication Allows Privilege Escalationmicrochip · istax · CWE-331 | Yüksek8,7 | — | %0,2 | 16 Nis 2026 |
34İzleyin | CVE-2024-43683İstismar yok | Improper verification of the Host header in TimeProvider 4100microchip · timeprovider 4100 firmware · CWE-601 | Yüksek8,7 | — | %0,2 | 4 Eki 2024 |
34İzleyin | CVE-2024-43684İstismar yok | Cross-Site Request Forgery vulnerability in TimeProvider 4100microchip · timeprovider 4100 firmware · CWE-79 | Yüksek8,7 | — | %0,2 | 4 Eki 2024 |
30İzleyin | CVE-2020-12788İstismar yok | CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power analysis attacks.microchip · atsama5d21c-cu firmware · CWE-203 | Yüksek7,5 | — | %1,3 | 14 Eyl 2020 |
30İzleyin | CVE-2021-37605İstismar yok | In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Mesmicrochip · miwi · CWE-670 | Yüksek7,5 | — | %1,3 | 5 Ağu 2021 |
30İzleyin | CVE-2020-12789İstismar yok | The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.microchip · atsama5d21c-cu firmware · CWE-798 | Yüksek7,5 | — | %1,2 | 14 Eyl 2020 |
30İzleyin | CVE-2020-12787İstismar yok | Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling.microchip · atsama5d21c-cu firmware | Yüksek7,5 | — | %1,2 | 14 Eyl 2020 |
30İzleyin | CVE-2021-37604İstismar yok | In version 6.5 of Microchip MiWi software and all previous versions including legacy products, there is a possibility of frame counters beinmicrochip · miwi · CWE-670 | Yüksek7,5 | — | %1,2 | 5 Ağu 2021 |
30İzleyin | CVE-2020-9034İstismar yok | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to umicrochip · syncserver s100 firmware | Yüksek7,5 | — | %0,9 | 16 Şub 2020 |
- CVE-2022-4002267Bu hafta
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
KritikCVSS 9,8SilahlaştırılmışEPSS %92microchip · syncserver s650 firmware13 Şub 2023
- CVE-2009-160840Planlayın
Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrar
KritikCVSS 9,3Kavram kanıtıEPSS %11microchip · mplab ide11 May 2009
- CVE-2024-2221640Planlayın
In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for
KritikCVSS 10,0İstismar yokEPSS %1microchip · maxview storage manager8 Oca 2024
- CVE-2024-905439İzleyin
Remote code Execution inTimeProvider® 4100
YüksekCVSS 8,5Kavram kanıtıEPSS %16microchip · timeprovider 4100 firmware4 Eki 2024
- CVE-2023-5143839İzleyin
A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC
KritikCVSS 9,8İstismar yokEPSS %1microchip · maxview storage manager9 Oca 2024
- CVE-2020-1744138İzleyin
An issue was discovered in picoTCP 1.7.0.
KritikCVSS 9,1İstismar yokEPSS %7altran · picotcp11 Ara 2020
- CVE-2009-167438İzleyin
Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof path
KritikCVSS 9,3Kavram kanıtıEPSS %5microchip · mplab ide18 May 2009
- CVE-2024-749038İzleyin
Remote Code Execution in Advanced Software Framework DHCP server
KritikCVSS 9,5İstismar yokEPSS %1microchip · advanced software framework8 Ağu 2024
- CVE-2019-1612737İzleyin
Atmel Advanced Software Framework (ASF) 4 has an Integer Overflow.
KritikCVSS 9,1İstismar yokEPSS %2microchip · advanced software framework 422 Eki 2020
- CVE-2026-284437İzleyin
TimePictra Authentication Bypass Vulnerability
KritikCVSS 9,3İstismar yokEPSS %0microchip · timepictra28 Şub 2026
- CVE-2026-301037İzleyin
TimePictra Stored Cross-Site Scripting
KritikCVSS 9,3İstismar yokEPSS %0microchip · timepictra28 Şub 2026
- CVE-2020-2763636İzleyin
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
KritikCVSS 9,1İstismar yokEPSS %1microchip · mplab network creator10 Eki 2023
- CVE-2025-4790035İzleyin
RCE on backup configuration password
YüksekCVSS 8,9İstismar yokEPSS %1microchip · timeprovider 4100 firmware20 Eki 2025
- CVE-2025-4790135İzleyin
RCE on restore configuration password
YüksekCVSS 8,9İstismar yokEPSS %1microchip · timeprovider 4100 firmware20 Eki 2025
- CVE-2022-4640334İzleyin
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages.
YüksekCVSS 8,6İstismar yokEPSS %1microchip · bm78 firmware19 Ara 2022
- CVE-2024-4368534İzleyin
Session token fixation in TimeProvider 4100
YüksekCVSS 8,7İstismar yokEPSS %0microchip · timeprovider 4100 firmware4 Eki 2024
- CVE-2026-233634İzleyin
Weak webstax_auth Cookie Authentication Allows Privilege Escalation
YüksekCVSS 8,7İstismar yokEPSS %0microchip · istax16 Nis 2026
- CVE-2024-4368334İzleyin
Improper verification of the Host header in TimeProvider 4100
YüksekCVSS 8,7İstismar yokEPSS %0microchip · timeprovider 4100 firmware4 Eki 2024
- CVE-2024-4368434İzleyin
Cross-Site Request Forgery vulnerability in TimeProvider 4100
YüksekCVSS 8,7İstismar yokEPSS %0microchip · timeprovider 4100 firmware4 Eki 2024
- CVE-2020-1278830İzleyin
CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power analysis attacks.
YüksekCVSS 7,5İstismar yokEPSS %1microchip · atsama5d21c-cu firmware14 Eyl 2020
- CVE-2021-3760530İzleyin
In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Mes
YüksekCVSS 7,5İstismar yokEPSS %1microchip · miwi5 Ağu 2021
- CVE-2020-1278930İzleyin
The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.
YüksekCVSS 7,5İstismar yokEPSS %1microchip · atsama5d21c-cu firmware14 Eyl 2020
- CVE-2020-1278730İzleyin
Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling.
YüksekCVSS 7,5İstismar yokEPSS %1microchip · atsama5d21c-cu firmware14 Eyl 2020
- CVE-2021-3760430İzleyin
In version 6.5 of Microchip MiWi software and all previous versions including legacy products, there is a possibility of frame counters bein
YüksekCVSS 7,5İstismar yokEPSS %1microchip · miwi5 Ağu 2021
- CVE-2020-903430İzleyin
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to u
YüksekCVSS 7,5İstismar yokEPSS %1microchip · syncserver s100 firmware16 Şub 2020