PT-2025-42797 · Microchip · Microchip Timeprovider 4100

Andrea Sindoni

+8

·

Published

2025-10-20

·

Updated

2025-10-20

·

CVE-2025-47902

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microchip Time Provider 4100 versions prior to 2.5
Description An improper neutralization of special elements used in an SQL command ('SQL Injection') issue exists in Microchip Time Provider 4100. This allows for SQL Injection. The vulnerability is present in the web resource. The SQL command is not properly sanitized, potentially allowing an attacker to inject malicious code.
Recommendations Update Microchip Time Provider 4100 to version 2.5 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-47902

Affected Products

Microchip Timeprovider 4100