Disclosed
CVE-2021-37605
In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Message Integrity Check (MIC) bytes.
Exploitation Probability (EPSS)
Low Priority0.47%
The Exploit Prediction Scoring System (EPSS) uses machine learning to estimate the probability that a vulnerability will be exploited in the wild within the next 30 days.
0% (Theoretical)100% (Certainty)
7-Day Exploitation Trend
Vulnerability Timeline
2 eventsAug 5, 2021
Vulnerability Disclosed
Published to component-level vulnerability database.
Jul 12, 2022
Last Updated
Record updated with new analysis or tags.
Threat Actor Attribution
PREMIUM INTELAssociated Groups:Lazarus Group, APT28
Ransomware Campaigns:LockBit 3.0, BlackCat
IoCs (Indicators):14 IPs, 3 Hashes
Remediation & Mitigation
SOLUTIONOfficial patches and mitigation steps are available for this vulnerability.
# Update Command
apt-get update && apt-get upgrade -y specific-package
# Verify installation
dpkg -l | grep package-name
apt-get update && apt-get upgrade -y specific-package
# Verify installation
dpkg -l | grep package-name
Affected Products
1 Total
microchip/miwi6.5
References
https://ww1.microchip.com/downloads/en/DeviceDoc/asf-release-notes-3.50.0.100-readme.pdfMicrochip
Vendor Advisory
https://ww1.microchip.com/downloads/en/DeviceDoc/asf-release-notes-3.51.0.101-readme.pdfMicrochip
Release NotesVendor Advisory
https://www.microchip.com/en-us/development-tools-tools-and-software/libraries-code-examples-and-more/advanced-software-framework-for-sam-devices#DownloadsMicrochip
Vendor Advisory
https://www.microchip.com/en-us/products/wireless-connectivity/software-vulnerability-response/miwi-software-vulnerabilityMicrochip
Vendor Advisory
Am I Vulnerable?
Check your domain or package.json for CVE-2021-37605 exposure.
Vulnerability Details
CVSS Base Score
7.5/ 10
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Published Date
Aug 5, 2021
Last Modified
Jul 12, 2022
Need Manual Validation?
Automated scanners flag false positives. Get a manual pentest validation for this CVE.