Microchip Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Microchip products.
Products
- TimeProvider 41007 vulnerabilities
- Time Provider 41005 vulnerabilities
- GridTime 30004 vulnerabilities
- timeprovider_4100_firmware4 vulnerabilities
- TimePictra2 vulnerabilities
- advanced_software_framework1 vulnerability
- IStaX1 vulnerability
- mplab_harmony1 vulnerability
- MPLAB® Harmony 3 Core Module1 vulnerability
- RN48701 vulnerability
- SAM3N1 vulnerability
- SAM3S1 vulnerability
- SAM3U1 vulnerability
- SAM4C1 vulnerability
- SAM4E1 vulnerability
- SAM4N1 vulnerability
- SAM4S1 vulnerability
- SAME701 vulnerability
- SAMG551 vulnerability
- SAMS701 vulnerability
- SAMV701 vulnerability
- SAMV711 vulnerability
- syncserver_s650_firmware1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-12620MEDIUM | Access Token Exposure in URL Parameters in GridTime™ 3000 GNSS Time ServerThe GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. CWE-200Jun 19, 2026 | CVSS4.6v4.0 | EPSS0.227% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12621MEDIUM | Cross-Site Scripting (XSS) Vulnerability in Password Reset Redirect in GridTime™ 3000 GNSS Time ServerImproper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form) allows XSS. This issue affects GridTime 3000: from 1.0r0.03 before 1.2r0.0. CWE-79Jun 19, 2026 | CVSS5.3v4.0 | EPSS0.136% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12622MEDIUM | Open Redirect Vulnerability in Password Reset Submission in GridTime™ 3000 GNSS Time ServerThe GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. CWE-601Jun 19, 2026 | CVSS5.3v4.0 | EPSS0.122% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12619MEDIUM | GridTime™ 3000 GNSS Time Server CSRF to XSSImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Site Scripting (XSS). This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. CWE-79Jun 19, 2026 | CVSS5.1v4.0 | EPSS0.136% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2336HIGH | Weak webstax_auth Cookie Authentication Allows Privilege EscalationA privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privileges.This issue affects IStaX before 2026.03. CWE-331Apr 16, 2026 | CVSS8.7v4.0 | EPSS0.232% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-9497MEDIUM | Hardcoded Upgrade Decryption PasswordsUse of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0. CWE-798Mar 28, 2026 | CVSS5.5v4.0 | EPSS0.277% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-3010CRITICAL | TimePictra Stored Cross-Site ScriptingImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimePictra allows Query System for Information.This issue affects TimePictra: from 11.0 through 11.3 SP2. CWE-79Feb 28, 2026 | CVSS9.3v4.0 | EPSS0.152% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2844CRITICAL | TimePictra Authentication Bypass VulnerabilityMissing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects TimePictra: from 11.0 through 11.3 SP2. CWE-306Feb 28, 2026 | CVSS9.3v4.0 | EPSS0.25% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-47904MEDIUM | Generated title:Microchip Time Provider 4100 Download of Code Without Integrity CheckDownload of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5. CWE-494Feb 24, 2026 | CVSS5.7v4.0 | EPSS0.082% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-47902HIGH | SQL Injection in web resourceImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injection.This issue affects Time Provider 4100: before 2.5. CWE-89Oct 20, 2025 | CVSS7.1v4.0 | EPSS0.353% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-47901HIGH | RCE on restore configuration passwordImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5. CWE-78Oct 20, 2025 | CVSS8.9v4.0 | EPSS1.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-47900HIGH | RCE on backup configuration passwordImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5. CWE-78Oct 20, 2025 | CVSS8.9v4.0 | EPSS1.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29155MEDIUM | Denial of service on Microchip RN4870 devicesOn Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device becomes incapable of completing the pairing process. A third party can inject a second PairReqNoInputNoOutput request just after a real one, causing the pair request to be blocked. | CVSS4.3v3.1 | EPSS0.234% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43683HIGH | Improper verification of the Host header in TimeProvider 4100URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects TimeProvider 4100: from 1.0. CWE-601Oct 4, 2024 | CVSS8.7v4.0 | EPSS0.211% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43684HIGH | Cross-Site Request Forgery vulnerability in TimeProvider 4100Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0. | CVSS8.7v4.0 | EPSS0.194% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43685HIGH | Session token fixation in TimeProvider 4100Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | CVSS8.7v4.0 | EPSS0.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43686MEDIUM | Reflected XSS in TimeProvider 4100 chart componentImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot modules) allows Reflected XSS.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. CWE-79Oct 4, 2024 | CVSS5.4v4.0 | EPSS11.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-9054HIGH | Remote code Execution inTimeProvider® 4100Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | CVSS8.5v4.0 | EPSS15% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43687HIGH | XSS vulnerability in bannerconfig endpoint in TimeProvider 4100Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0 before 2.4.7. CWE-79Oct 4, 2024 | CVSS7.7v4.0 | EPSS0.786% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-7801MEDIUM | SQL injection in get_chart_data in TimeProvider 4100Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules) allows SQL Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. CWE-89Oct 4, 2024 | CVSS6.3v4.0 | EPSS0.843% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-7490CRITICAL | Remote Code Execution in Advanced Software Framework DHCP serverImproper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software Framework: through 3.52.0.2574. ASF is no longer being supported. Apply provided workaround or migrate to an actively maintained framework. CWE-120Aug 8, 2024 | CVSS9.5v4.0 | EPSS1.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30212HIGH | Microchip Harmony 3 Core library allows read and write access to RAM via a SCSI READ or WRITE commandIf a SCSI READ(10) command is initiated via USB using the largest LBA (0xFFFFFFFF) with it's default block size of 512 and a count of 1, the first 512 byte of the 0x80000000 memory area is returned to the user. If the block count is increased, the full RAM can be exposed. The same method works to write to this memory area. If RAM contains pointers, those can be - depending on the application - overwritten to return data from any other offset including Progam and Boot Flash. CWE-190May 28, 2024 | CVSS7.0v4.0 | EPSS0.568% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-4760MEDIUM | Voltage glitch during startup of the EEFC NVM controller can bypass the security bitA voltage glitch during the startup of EEFC NVM controllers on Microchip SAM E70/S70/V70/V71, SAM G55, SAM 4C/4S/4N/4E, and SAM 3S/3N/3U microcontrollers allows access to the memory bus via the debug interface even if the security bit is set. CWE-1247May 16, 2024 | CVSS6.3v3.1 | EPSS0.209% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-40022CRITICAL | microchip syncserver_s650_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability. | CVSS9.8v3.1 | EPSS92.5% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |