CVE-2024-9054
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Oct 4, 2024
Updated: Oct 17, 2024
CWE ID 78
CWE ID 200
Summary
CVE-2024-9054 is a critical vulnerability affecting Microchip's TimeProvider 4100 configuration modules. The issue involves improper neutralization of special elements in OS commands, leading to Command Injection. This security flaw allows unauthorized actors to execute arbitrary OS commands and gain sensitive information, posing a significant risk. Affected versions of TimeProvider 4100 range from 1.0 to 2.4.6. Users are strongly urged to update to the latest version, 2.4.7, to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.