← Back

Microchip

microchip

53 CVEs • 211 products

Products (211)

Click to collapse
Toggle
Bm78 Firmware
bm78_firmware
Bm83 Firmware
bm83_firmware
Bm70 Firmware
bm70_firmware
Bm71 Firmware
bm71_firmware
Mplab Ide
mplab_ide
Cryptoauthlib
cryptoauthlib
Miwi
miwi
Bm64 Firmware
bm64_firmware
Bm77 Firmware
bm77_firmware

CVEs (53)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microchip
76Atsama5d21c Cu Firmware
Atsama5d21c Cur FirmwareAtsama5d225c D1m Cur Firmware+73 more
Jun 17, 2026
Sep 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power analysis attacks.
1Microchip
76Atsama5d21c Cu Firmware
Atsama5d21c Cur FirmwareAtsama5d225c D1m Cur Firmware+73 more
Jun 17, 2026
Sep 14, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling.
1Microchip
5Syncserver S100 Firmware
Syncserver S200 FirmwareSyncserver S250 Firmware+2 more
Jun 17, 2026
Feb 17, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to authlog.php.
1Microchip
5Syncserver S100 Firmware
Syncserver S200 FirmwareSyncserver S250 Firmware+2 more
Jun 17, 2026
Feb 17, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to kernlog.php.
1Microchip
5Syncserver S100 Firmware
Syncserver S200 FirmwareSyncserver S250 Firmware+2 more
Jun 17, 2026
Feb 17, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to daemonlog.php.
1Microchip
5Syncserver S100 Firmware
Syncserver S200 FirmwareSyncserver S250 Firmware+2 more
Jun 17, 2026
Feb 17, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to the syslog.php.
1Microchip
5Syncserver S100 Firmware
Syncserver S200 FirmwareSyncserver S250 Firmware+2 more
Jun 17, 2026
Feb 17, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messagelog.php.
1Microchip
5Syncserver S100 Firmware
Syncserver S200 FirmwareSyncserver S250 Firmware+2 more
Jun 17, 2026
Feb 17, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User Creation, Deletion and Password Maintenance" screen (when crea...Show more
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User Creation, Deletion and Password Maintenance" screen (when creating a new user).Show less
1Microchip
5Syncserver S100 Firmware
Syncserver S200 FirmwareSyncserver S250 Firmware+2 more
Jun 17, 2026
Feb 17, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenticated creation, modification, or elimination of users.
1Microchip
1Atmsamb11 Blusdk Smart
Jun 17, 2026
Feb 10, 2020
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
The Bluetooth Low Energy implementation on Microchip Technology BluSDK Smart through 6.2 for ATSAMB11 devices does not properly restrict link-layer data length on reception, allowing attackers in radio range to cause a d...Show more
The Bluetooth Low Energy implementation on Microchip Technology BluSDK Smart through 6.2 for ATSAMB11 devices does not properly restrict link-layer data length on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.Show less
5Athena Scs
CryptsoftMicrochip+2 more
5Armored Card
Atmel ToolboxEtoken 4300+2 more
Jun 17, 2026
Oct 3, 2019
N/A· v4
4.7 MEDIUM· v3
1.2 LOW· v2
Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to measure the dur...Show more
Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because the Atmel Toolbox 00.03.11.05 contains two versions of ECDSA signature functions, described as fast and secure, but the affected cards chose to use the fast version, which leaks the bit length of the random nonce via timing. This affects Athena IDProtect 010b.0352.0005, Athena IDProtect 010e.1245.0002, Athena IDProtect 0106.0130.0401, Athena IDProtect 010e.1245.0002, Valid S/A IDflex V 010b.0352.0005, SafeNet eToken 4300 010e.1245.0002, TecSec Armored Card 010e.0264.0001, and TecSec Armored Card 108.0264.0001.Show less
1Microchip
1Mplab Ide
Apr 23, 2026
May 18, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathname in a [TOOL_SETTINGS] section in a .mcp file, possibly a related issue to CV...Show more
Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathname in a [TOOL_SETTINGS] section in a .mcp file, possibly a related issue to CVE-2009-1608.Show less
1Microchip
1Mplab Ide
Apr 23, 2026
May 11, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code via a .MCP project file with long (1) FILE_INFO, (2) CAT_FILTERS, and pos...Show more
Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code via a .MCP project file with long (1) FILE_INFO, (2) CAT_FILTERS, and possibly other fields.Show less