CVE-2025-9497: Hardcoded Upgrade Decryption Passwords
Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9497?
CVE-2025-9497 is rated as a high severity vulnerability due to the use of hard-coded credentials that allow for unauthorized manual software updates.
How do I fix CVE-2025-9497?
To mitigate CVE-2025-9497, upgrade your Microchip Time Provider 4100 to version 2.5.0 or later, which addresses the hard-coded credential issue.
What products are affected by CVE-2025-9497?
CVE-2025-9497 affects the Microchip Time Provider 4100 versions prior to 2.5.0.
Can CVE-2025-9497 lead to unauthorized access?
Yes, CVE-2025-9497 can potentially lead to unauthorized access as the hard-coded passwords may allow attackers to perform malicious software updates.
Is there a workaround for CVE-2025-9497?
There are no effective workarounds for CVE-2025-9497; the best course of action is to update to the fixed version.