Cross-site Scripting (XSS) Vulnerability in Microchip TimeProvider 4100
CVE-2024-43686

6.1MEDIUM

Key Information:

Vendor

Microchip

Vendor
CVE Published:
4 October 2024

What is CVE-2024-43686?

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot modules) allows Reflected XSS.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.
CVE-2024-43686 : Cross-site Scripting (XSS) Vulnerability in Microchip TimeProvider 4100