CVE-2024-43683: Improper verification of the Host header in TimeProvider 4100
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects TimeProvider 4100: from 1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43683?
CVE-2024-43683 is classified as a medium-severity vulnerability due to its potential to allow URL redirection to untrusted sites.
How do I fix CVE-2024-43683?
To fix CVE-2024-43683, it is recommended to upgrade the Microchip TimeProvider 4100 firmware to version 2.4.7 or later.
What systems are affected by CVE-2024-43683?
CVE-2024-43683 affects Microchip TimeProvider 4100 firmware versions from 1.0 to 2.4.6.
What are the risks associated with CVE-2024-43683?
The risks associated with CVE-2024-43683 include possible exploitation for cross-site scripting (XSS) attacks through manipulated HTTP headers.
Is there a workaround for CVE-2024-43683?
There is no official workaround for CVE-2024-43683, and upgrading the firmware is the recommended course of action.