Show filters
47 Total Results
Displaying 11-20 of 47
Sort by:
Attacker Value
Unknown

CVE-2024-30212

Disclosure Date: May 28, 2024 (last updated May 29, 2024)
If a SCSI READ(10) command is initiated via USB using the largest LBA (0xFFFFFFFF) with it's default block size of 512 and a count of 1, the first 512 byte of the 0x80000000 memory area is returned to the user. If the block count is increased, the full RAM can be exposed. The same method works to write to this memory area. If RAM contains pointers, those can be - depending on the application - overwritten to return data from any other offset including Progam and Boot Flash.
0
Attacker Value
Unknown

CVE-2024-4760

Disclosure Date: May 16, 2024 (last updated May 17, 2024)
A voltage glitch during the startup of EEFC NVM controllers on Microchip SAM E70/S70/V70/V71 microcontrollers allows access to the memory bus via the debug interface even if the security bit is set.
0
Attacker Value
Unknown

CVE-2023-51438

Disclosure Date: January 09, 2024 (last updated January 17, 2024)
A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC847E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows). In default installations of maxView Storage Manager where Redfish® server is configured for remote system management, a vulnerability has been identified that can provide unauthorized access.
Attacker Value
Unknown

CVE-2024-22216

Disclosure Date: January 08, 2024 (last updated February 16, 2024)
In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote system management, unauthorized access can occur, with data modification and information disclosure. This affects 3.00.23484 through 4.14.00.26064 (except for the patched versions 3.07.23980 and 4.07.00.25339).
Attacker Value
Unknown

CVE-2020-27636

Disclosure Date: October 10, 2023 (last updated October 14, 2023)
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
Attacker Value
Unknown

CVE-2023-23588

Disclosure Date: April 11, 2023 (last updated January 12, 2024)
A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC647D (All versions), SIMATIC IPC647E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC847D (All versions), SIMATIC IPC847E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows). The Adaptec Maxview application on affected devices is using a non-unique TLS certificate across installations to protect the communication from the local browser to the local application. A local attacker may use this key to decrypt intercepted local traffic between the browser and the application and could perform a man-in-the-middle attack in order to modify data in transit.
Attacker Value
Unknown

CVE-2022-40022

Disclosure Date: February 13, 2023 (last updated October 08, 2023)
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
Attacker Value
Unknown

CVE-2022-45192

Disclosure Date: February 08, 2023 (last updated October 08, 2023)
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a cleartext encryption pause request.
Attacker Value
Unknown

CVE-2022-45191

Disclosure Date: February 08, 2023 (last updated October 08, 2023)
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a pair confirm message with wrong values.
Attacker Value
Unknown

CVE-2022-45190

Disclosure Date: February 08, 2023 (last updated October 08, 2023)
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device.