This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option.
This issue affects Advanced Software Framework: through 3.52.0.2574.
ASF is no longer being supported. Apply provided workaround or migrate to an actively maintained framework.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48404 | Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software Framework: through 3.52.0.2574. ASF is no longer being supported. Apply provided workaround or migrate to an actively maintained framework. |
Solution
ASF is no longer being supported. Apply provided workaround or migrate to an actively maintained framework.
Workaround
The issue can be mitigated by adding a check to the size variable after the call [1] to pbuf_get_at on line 127 [1]. If the size variable is not 4, then the function should cease processing and return. The lwip_dhcp_find_option function is only used to find this one option. [1] https://github.com/alfred-ai/microchip-asf/blob/bf5205e36a265b867d531647ffbf2de5e287853a/thirdparty/lwip/lwip-tinyservices/tinydhcpserver.c#L127
Sat, 30 Aug 2025 06:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Fri, 22 Nov 2024 21:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 13 Aug 2024 00:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 09 Aug 2024 02:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microchip
Microchip advanced Software Framework |
|
| CPEs | cpe:2.3:a:microchip:advanced_software_framework:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microchip
Microchip advanced Software Framework |
|
| Metrics |
ssvc
|
Fri, 09 Aug 2024 01:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software Framework: through 3.52.0.2574. | Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software Framework: through 3.52.0.2574. ASF is no longer being supported. Apply provided workaround or migrate to an actively maintained framework. |
Fri, 09 Aug 2024 00:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software Framework: through 3.52.0.2574. | |
| Title | Remote Code Execution in Advanced Software Framework DHCP server | |
| Weaknesses | CWE-120 CWE-20 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Microchip
Published:
Updated: 2025-08-29T20:23:53.142Z
Reserved: 2024-08-05T14:10:12.165Z
Link: CVE-2024-7490
Updated: 2024-09-19T13:06:47.103Z
Status : Analyzed
Published: 2024-08-08T15:15:19.057
Modified: 2025-09-29T21:40:55.453
Link: CVE-2024-7490
No data.
OpenCVE Enrichment
No data.
EUVD