CVE-2026-12619: GridTime™ 3000 GNSS Time Server CSRF to XSS
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Site Scripting (XSS).
This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Microchip GridTime 3000 GNSS Time Serverto a version that resolves this vulnerability.Fixed in 1.2r0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12619?
The severity of CVE-2026-12619 is rated as medium, with a CVSS score of 5.1.
What type of vulnerability is associated with CVE-2026-12619?
CVE-2026-12619 is associated with Cross-Site Scripting (XSS) vulnerabilities.
How do I fix CVE-2026-12619?
To fix CVE-2026-12619, update the Microchip GridTime 3000 to a version where the vulnerability has been addressed.
Which versions of Microchip GridTime 3000 are affected by CVE-2026-12619?
CVE-2026-12619 affects Microchip GridTime 3000 versions from 1.0r0.03 to 1.1r0.0.
What is the impact of CVE-2026-12619 on users?
The impact of CVE-2026-12619 may allow an attacker to inject malicious scripts into web pages viewed by users, potentially compromising their data.