VulnerabilityModified
CVE-2019-16127
Atmel Advanced Software Framework (ASF) 4 has an Integer Overflow.
CRITICAL 9.1EPSS 1.98%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.98%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Atmel Advanced Software Framework (ASF) 4 has an Integer Overflow.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 1.98% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- microchip/advanced software framework 4
- Source
- cve@mitre.org
References
- https://census-labs.com/news/2020/10/21/microchip-asf4-integer-overflows-in-flash_read-flash_write-and-flash_append/Exploit, Press/Media Coverage, Third Party Advisory
- https://www.microchip.com/mplab/avr-support/advanced-software-frameworkProduct, Vendor Advisory
- https://www.openwall.com/lists/oss-security/2020/10/22/1Mailing List, Third Party Advisory
- https://census-labs.com/news/2020/10/21/microchip-asf4-integer-overflows-in-flash_read-flash_write-and-flash_append/Exploit, Press/Media Coverage, Third Party Advisory
- https://www.microchip.com/mplab/avr-support/advanced-software-frameworkProduct, Vendor Advisory
- https://www.openwall.com/lists/oss-security/2020/10/22/1Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.