CVE-2024-7490
Severity CVSS v4.0:
CRITICAL
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
08/08/2024
Last modified:
29/09/2025
Description
Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow.<br />
This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option.<br />
<br />
This issue affects Advanced Software Framework: through 3.52.0.2574.<br />
<br />
<br />
ASF is no longer being supported. Apply provided workaround or migrate to an actively maintained framework.
Impact
Base Score 4.0
9.50
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:microchip:advanced_software_framework:*:*:*:*:*:*:*:* | 3.52.0.2574 (including) |
To consult the complete list of CPE names with products and versions, see this page



