Microchip TimeProvider 4100是美国微芯科技(Microchip)公司的一种网关时钟。 Microchip TimeProvider 4100 2.4.7之前版本存在安全漏洞,该漏洞源于操作系统命令的特殊元素中和不当,导致OS命令注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microchip | TimeProvider 4100 | 1.0 ~ 2.4.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-7801 | SQL injection in get_chart_data in TimeProvider 4100 | |
| CVE-2024-43687 | XSS vulnerability in bannerconfig endpoint in TimeProvider 4100 | |
| CVE-2024-43685 | Session token fixation in TimeProvider 4100 | |
| CVE-2024-43684 | Cross-Site Request Forgery vulnerability in TimeProvider 4100 | |
| CVE-2024-43683 | Improper verification of the Host header in TimeProvider 4100 | |
| CVE-2024-43686 | Reflected XSS in TimeProvider 4100 chart component |
No comments yet