Microchip TimeProvider 4100 Vulnerability: URL Redirection to Untrusted Site
CVE-2024-43683

6.1MEDIUM

Key Information:

Vendor

Microchip

Vendor
CVE Published:
4 October 2024

What is CVE-2024-43683?

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects TimeProvider 4100: from 1.0.

Affected Version(s)

TimeProvider 4100 1.0 < 2.4.7

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

Credit

Armando Huesca Prida
Marco Negro
Antonio Carriero
Vito Pistillo
Davide Renna
Manuel Leone
Massimiliano Brolli
TIM Security Red Team Research
.
CVE-2024-43683 : Microchip TimeProvider 4100 Vulnerability: URL Redirection to Untrusted Site