Vulnerability index

Browse CVEs

26 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Mplab Network Creator CRITICAL 9.1
CVE-2020-27636

In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.

Mitigation only
Fix from $2,300 2023-10-10
Syncserver S650 Firmware CRITICAL 9.8
CVE-2022-40022EPSS 92%

Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.

No fix yet
Fix from $2,300 2023-02-13
Dt100112 Firmware MEDIUM 6.5
CVE-2022-40480

Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service…

Mitigation only
Fix from $1,600 2023-02-08
Rn4870 Firmware MEDIUM 6.5
CVE-2022-45191

An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a pair confirm …

Mitigation only
Fix from $1,600 2023-02-08
Rn4870 Firmware MEDIUM 6.5
CVE-2022-45192

An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a cleartext enc…

Mitigation only
Fix from $1,600 2023-02-08
Rn4870 Firmware MEDIUM 5.3
CVE-2022-45190

An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the de…

Mitigation only
Fix from $1,600 2023-02-08
Bm78 Firmware HIGH 8.6
CVE-2022-46403

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages.

No fix yet
Fix from $1,950 2022-12-19
Bm78 Firmware MEDIUM 6.5
CVE-2022-46402

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_rmSend with incorrect values.

No fix yet
Fix from $1,600 2022-12-19
Bm78 Firmware MEDIUM 5.4
CVE-2022-46401

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is…

No fix yet
Fix from $1,600 2022-12-19
Bm78 Firmware HIGH 7.5
CVE-2022-46399

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero.

No fix yet
Fix from $1,950 2022-12-19
Bm78 Firmware MEDIUM 5.4
CVE-2022-46400

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in le…

No fix yet
Fix from $1,600 2022-12-19
Miwi HIGH 7.5
CVE-2021-37604

In version 6.5 of Microchip MiWi software and all previous versions including legacy products, there is a possibility of frame counters being validat…

Mitigation only
Fix from $1,950 2021-08-05
Miwi HIGH 7.5
CVE-2021-37605

In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Message Inte…

Mitigation only
Fix from $1,950 2021-08-05
Advanced Software Framework 4 CRITICAL 9.1
CVE-2019-16127

Atmel Advanced Software Framework (ASF) 4 has an Integer Overflow.

No fix yet
Fix from $2,300 2020-10-22
Atsama5d21c Cu Firmware HIGH 7.5
CVE-2020-12787

Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling.

Mitigation only
Fix from $1,950 2020-09-14
Atsama5d21c Cu Firmware HIGH 7.5
CVE-2020-12788

CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power analysis attacks.

Mitigation only
Fix from $1,950 2020-09-14
Atsama5d21c Cu Firmware HIGH 7.5
CVE-2020-12789

The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.

Mitigation only
Fix from $1,950 2020-09-14
Syncserver S100 Firmware MEDIUM 6.5
CVE-2020-9029

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName paramete…

No fix yet
Fix from $1,600 2020-02-17
Syncserver S100 Firmware MEDIUM 6.5
CVE-2020-9030

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName paramete…

No fix yet
Fix from $1,600 2020-02-17
Syncserver S100 Firmware MEDIUM 6.5
CVE-2020-9031

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName paramete…

No fix yet
Fix from $1,600 2020-02-17
Syncserver S100 Firmware MEDIUM 6.5
CVE-2020-9032

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName paramete…

No fix yet
Fix from $1,600 2020-02-17
Syncserver S100 Firmware MEDIUM 6.5
CVE-2020-9033

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName paramete…

No fix yet
Fix from $1,600 2020-02-17
Syncserver S100 Firmware MEDIUM 6.1
CVE-2020-9028

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on t…

No fix yet
Fix from $1,600 2020-02-17
Syncserver S100 Firmware HIGH 7.5
CVE-2020-9034

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenti…

No fix yet
Fix from $1,950 2020-02-17
Mplab Ide HIGH 9.3
CVE-2009-1674

Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathname in a…

No fix yet
Fix from $1,950 2009-05-18
Mplab Ide HIGH 9.3
CVE-2009-1608EPSS 11%

Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code vi…

No fix yet
Fix from $1,950 2009-05-11