VYPR

Vendor CVEs

Microchip

All CVEs

62 total · sorted by risk
  • CVE-2022-46401MedDec 19, 2022
    risk 0.35cvss 5.4epss 0.01

    The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.

  • CVE-2022-46400MedDec 19, 2022
    risk 0.35cvss 5.4epss 0.01

    The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing.

  • CVE-2022-45190MedFeb 8, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device.

  • CVE-2019-15809MedOct 3, 2019
    risk 0.31cvss 4.7epss 0.00

    Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to measure the duration of hundreds to thousands of signing operations, to…

  • CVE-2026-46148MedMay 28, 2026
    risk 0.29cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: spi: microchip-core-qspi: control built-in cs manually The coreQSPI IP supports only a single chip select, which is automagically operated by the hardware - set low when the transmit buffer first gets written…

  • CVE-2024-29155MedOct 16, 2024
    risk 0.28cvss 4.3epss 0.00

    On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device becomes incapable of completing the pairing process. A third party can inject a second PairReqNoInputNoOutput request just after a real one, causing the pair…

  • CVE-2025-47904MedFeb 24, 2026
    risk 0.27cvss 4.1epss 0.00

    Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.

  • CVE-2026-10644MedJun 28, 2026
    risk 0.20cvss 4.2epss 0.00

    The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mchp_sercom_g1.c), used by the PIC32CM-JH SoC family, contains an out-of-bounds write in its asynchronous (DMA) receive path. When uart_rx_enable() is invoked with a one-byte receive buffer (len == 1) and…

  • CVE-2009-1608May 11, 2009
    risk 0.04cvss epss 0.11

    Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code via a .MCP project file with long (1) FILE_INFO, (2) CAT_FILTERS, and possibly other fields.

  • CVE-2009-1674May 18, 2009
    risk 0.03cvss epss 0.05

    Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathname in a [TOOL_SETTINGS] section in a .mcp file, possibly a related issue to CVE-2009-1608.

  • CVE-2020-11684CriSep 14, 2020
    risk 0.00cvss 9.1epss 0.01

    AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose these keys and subsequently encrypt and sign the next boot stage (such as the…

  • CVE-2020-11683MedSep 14, 2020
    risk 0.00cvss 6.8epss 0.01

    A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical access to forge CMAC values and subsequently boot arbitrary code on an affected system.

Page 2 of 2