PT-2024-30613 · Microchip · Timeprovider 4100

Antonio Carriero

+6

·

Published

2024-10-04

·

Updated

2024-10-16

·

CVE-2024-43686

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Microchip TimeProvider 4100 versions 1.0 through 2.4.7
Description The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). This allows for Reflected XSS attacks. The vulnerability is present in the data plot modules of the affected software.
Recommendations For versions 1.0 through 2.4.7, update to version 2.4.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the data plot modules until a patch is applied. Avoid using the vulnerable data plot modules in the affected API endpoints until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-43686

Affected Products

Timeprovider 4100