First published: Fri Oct 04 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules) allows SQL Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.
Credit: dc3f6da9-85b5-4a73-84a2-2ec90b40fca5
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Microchip Timeprovider 4100 Grandmaster Firmware | >=1.0<2.4.7 | |
Microchip Timeprovider 4100 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7801 has a medium severity rating due to its potential for SQL injection attacks.
To fix CVE-2024-7801, upgrade your Microchip TimeProvider 4100 firmware to version 2.4.7 or later.
CVE-2024-7801 affects Microchip TimeProvider 4100 firmware versions from 1.0 up to but not including 2.4.7.
Yes, CVE-2024-7801 can potentially be exploited remotely if the attacker can interact with the affected SQL interface.
Exploiting CVE-2024-7801 can lead to unauthorized access to sensitive data through SQL injection.