CVE-2024-9054
8.5
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:AmberShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:AmberShow less
Source: dc3f6da9-85b5-4a73-84a2-2ec90b40fca5 (Secondary)
Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.
Affected (1)
Products: Microchip: Timeprovider 4100 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 2.4.7 |
| Running on/with | Platform Versions |
|---|---|
Microchip Timeprovider 4100 | All versions |
References (2)
Source: dc3f6da9-85b5-4a73-84a2-2ec90b40fca5
ExploitThird Party Advisory
Source: dc3f6da9-85b5-4a73-84a2-2ec90b40fca5
Vendor Advisory
Timeline
No history available yet.