← Vulnerability feed

Vulnerability record · CVE-2024-43686 · published 4 October 2024

CVE-2024-43686: Microchip timeprovider 4100 firmware cross-site scripting vulnerability

Microchip · Timeprovider 4100 Firmware

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot modules) allows Reflected XSS.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

5.4 CVSS 4.0 Medium EPSS 13% · top 3.8% CWE-79 · Cross-site scripting
5.4CVSS 4.0 base score
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot modules) allows Reflected XSS.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-43686 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.9CVE-2025-47900Microchip timeprovider 4100 firmware os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Co…EPSS 1.4%8.9CVE-2025-47901Microchip timeprovider 4100 firmware os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Co…EPSS 1.4%8.7CVE-2024-43683Microchip timeprovider 4100 firmware open redirect vulnerabilityURL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects T…EPSS 0.23%8.7CVE-2024-43684Microchip timeprovider 4100 firmware cross-site scripting vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This iss…EPSS 0.21%8.7CVE-2024-43685Microchip timeprovider 4100 firmware insufficient session expiration vulnerabilityImproper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: f…EPSS 0.44%8.5CVE-2024-9054Microchip timeprovider 4100 firmware os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Acto…EPSS 16%7.7CVE-2024-43687Microchip timeprovider 4100 firmware cross-site scripting vulnerabilityImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner conf…EPSS 0.83%7.1CVE-2025-47902Microchip timeprovider 4100 firmware sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injecti…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2024-43686), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.