Microchip Vulnerabilities and Affected Products
Vulnerabilities associated with mplab_harmony.
Products
Clear product- TimeProvider 41007 vulnerabilities
- Time Provider 41005 vulnerabilities
- GridTime 30004 vulnerabilities
- timeprovider_4100_firmware4 vulnerabilities
- TimePictra2 vulnerabilities
- advanced_software_framework1 vulnerability
- IStaX1 vulnerability
- mplab_harmony1 vulnerability
- MPLAB® Harmony 3 Core Module1 vulnerability
- RN48701 vulnerability
- SAM3N1 vulnerability
- SAM3S1 vulnerability
- SAM3U1 vulnerability
- SAM4C1 vulnerability
- SAM4E1 vulnerability
- SAM4N1 vulnerability
- SAM4S1 vulnerability
- SAME701 vulnerability
- SAMG551 vulnerability
- SAMS701 vulnerability
- SAMV701 vulnerability
- SAMV711 vulnerability
- syncserver_s650_firmware1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-30212HIGH | Microchip Harmony 3 Core library allows read and write access to RAM via a SCSI READ or WRITE commandIf a SCSI READ(10) command is initiated via USB using the largest LBA (0xFFFFFFFF) with it's default block size of 512 and a count of 1, the first 512 byte of the 0x80000000 memory area is returned to the user. If the block count is increased, the full RAM can be exposed. The same method works to write to this memory area. If RAM contains pointers, those can be - depending on the application - overwritten to return data from any other offset including Progam and Boot Flash. CWE-190May 28, 2024 | CVSS7.0v4.0 | EPSS0.568% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |