PT-2024-39392 · Microchip · Timeprovider 4100
Antonio Carriero
+6
·
Published
2024-10-04
·
Updated
2025-09-29
·
CVE-2024-9054
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microchip TimeProvider 4100 versions 1.0 through 2.4.7
Description
The issue affects the configuration modules of Microchip TimeProvider 4100, allowing Command Injection due to improper neutralization of special elements used in an OS command. This exposes sensitive information to unauthorized actors.
Recommendations
Update to version 2.4.7 or later to fix the issue. As a temporary workaround, consider restricting access to the configuration modules to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Timeprovider 4100