CVE-2024-43684: Cross-Site Request Forgery vulnerability in TimeProvider 4100
Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43684?
CVE-2024-43684 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can lead to exploitation of the affected system.
How do I fix CVE-2024-43684?
To mitigate CVE-2024-43684, users should upgrade to Microchip TimeProvider 4100 firmware version 2.4.7 or later.
What software is affected by CVE-2024-43684?
CVE-2024-43684 affects Microchip TimeProvider 4100 firmware versions from 1.0 to 2.4.6 inclusive.
What types of attacks does CVE-2024-43684 enable?
CVE-2024-43684 enables Cross-Site Request Forgery (CSRF) attacks, which can be exploited to perform unauthorized actions on behalf of users.
Is there a workaround for CVE-2024-43684?
Currently, there are no documented workarounds for CVE-2024-43684 other than upgrading the firmware.