Security teams were warned late last week that two different vulnerabilities in the drivers and libraries that chip manufacturers use to develop products on top of microcontrollers could lead to remote code execution (RCE).The first vulnerability — CVE-2024-7490 — reported Sept. 19 by the CERT Coordination Center at Carnegie Mellon University, was a critical 9.5 vulnerability in all publicly available examples of the Microchip Advanced Software Framework (ASF) codebase.Chip designers use the free, open-source code library from Microchip ASF to help them simplify the use of microcontrollers. The ASF gets used for evaluation, prototyping, design and production. CERT said the bug lets a specially crafted DHCP request cause a stack-based overflow that could lead to an RCE. Because this vulnerability is in IoT-centric code, CERT added that it’s likely to surface in many places in the wild. “In addition to the vulnerability allowing remote code execution, the real problem is that ASF is open-source and is in countless products without an easy way for researchers to enumerate a complete list of vulnerable products,” said John Bambenek, president of Bambenek Consulting.On the other hand, Bambenek said the flaw in DHCP means that security pros have a starting point of where to look. He said teams should have all devices log and monitor their DHCP and system logs to look for crashes. And any DHCP traffic outside of normal DHCP client requests should also be a good start for hunt teams to examine.“This is a reminder that DHCP is the soft underbelly of most networks and without strong controls of what gets on a network, there are limitless ways to engage in network-based attacks,” said Bambenek.John Gallagher, vice president of Viakoo Labs, said security teams should take three steps:First, deploy an IoT-oriented asset and application discovery tool so they have an accurate inventory. Second, make sure that all IoT/OT devices are on segmented networks of VLANs to prevent lateral movement. Finally, work with procurement to ensure that the device manufacturers are able to provide a patch to remediate the vulnerability.
Network Security, DevSecOps, Patch/Configuration Management![A gold-colored computer chip is seen on a motherboard surround by glowing lights and circuits](https://image-optimizer.cyberriskalliance.com/unsafe/1920x0/https://files.cyberriskalliance.com/wp-content/uploads/2024/09/092324_computer_chip.jpg)
Critical vulnerabilities in Microchip ASF, MediaTek expose RCE risks
![A gold-colored computer chip is seen on a motherboard surround by glowing lights and circuits](https://image-optimizer.cyberriskalliance.com/unsafe/1920x0/https://files.cyberriskalliance.com/wp-content/uploads/2024/09/092324_computer_chip.jpg)
(Adobe Stock)
An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds