PT-2024-30614 · Microchip · Timeprovider 4100

Antonio Carriero

+6

·

Published

2024-10-04

·

Updated

2024-10-16

·

CVE-2024-43687

CVSS v4.0

7.7

High

VectorAV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:P/AU:Y/R:U/V:D/U:Green
Name of the Vulnerable Software and Affected Versions Microchip TimeProvider 4100 versions 1.0 through 2.4.6
Description The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-Site Scripting (XSS). This security issue affects the banner config modules of the Microchip TimeProvider 4100, allowing Cross-Site Scripting (XSS).
Recommendations For versions 1.0 through 2.4.6, update to version 2.4.7 or later to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-43687

Affected Products

Timeprovider 4100