peter bassill · operator
$ cve CVE-2024-9054 JSON

CVE-2024-9054 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 15.6% (pctl 97)

Patch early

A public exploit exists.

Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS15.63% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2024-10-04
Last modified2026-06-17

Affected (2)

VendorProduct
microchiptimeprovider 4100
microchiptimeprovider 4100 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD