PT-2024-30611 · Microchip · Microchip Timeprovider 4100

·

CVE-2024-43684

·

Published

2024-10-04

·

Updated

2025-08-29

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microchip TimeProvider 4100 versions 1.0 and later
Description The issue is a Cross-Site Request Forgery (CSRF) vulnerability that also allows Cross-Site Scripting (XSS). This vulnerability affects the Microchip TimeProvider 4100, allowing for unauthorized actions to be performed on the device.
Recommendations For Microchip TimeProvider 4100 version 1.0 and later, update to a version that includes a fix for this issue. As a temporary workaround, consider implementing additional security measures to prevent CSRF attacks, such as validating request origins and using anti-CSRF tokens. Restrict access to sensitive functionality to minimize the risk of exploitation.

Fix

XSS

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-43684

Affected Products

Microchip Timeprovider 4100