CVE-2025-47901
8.9
Vector
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: dc3f6da9-85b5-4a73-84a2-2ec90b40fca5 (Secondary)
Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5.
Affected (1)
Products: Microchip: Timeprovider 4100 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.5 |
| Running on/with | Platform Versions |
|---|---|
Microchip Timeprovider 4100 | All versions |
References (2)
Source: dc3f6da9-85b5-4a73-84a2-2ec90b40fca5
Source: dc3f6da9-85b5-4a73-84a2-2ec90b40fca5
Vendor Advisory
Timeline
No history available yet.