CVE-2024-43685: Session token fixation in TimeProvider 4100
Published Oct 4, 2024
·Updated
Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.
Affected Software
2 affected components
All of the following
Microchip Timeprovider 4100 Firmware>=1.0<2.4.7
Microchip TimeProvider 4100
Event History
Oct 4, 2024
CVE Published
via MITRE·07:48 PM
Data Sourced
via MITRE·07:48 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-43685?
CVE-2024-43685 is classified as a high-severity vulnerability due to the potential for session hijacking.
2
How do I fix CVE-2024-43685?
To fix CVE-2024-43685, upgrade the Microchip TimeProvider 4100 firmware to version 2.4.7 or later.
3
What systems are affected by CVE-2024-43685?
CVE-2024-43685 affects Microchip TimeProvider 4100 firmware versions from 1.0 up to but not including 2.4.7.
4
What type of vulnerability is CVE-2024-43685?
CVE-2024-43685 is an improper authentication vulnerability that can lead to session hijacking.
5
Who should be concerned about CVE-2024-43685?
Organizations using Microchip TimeProvider 4100 prior to version 2.4.7 should be particularly concerned about CVE-2024-43685.