Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects TimePictra: from 11.0 through 11.3 SP2.
The vulnerability results from omission of an authentication mechanism for specific critical functions in the TimePictra application. A remote attacker, without the need to possess an account or permissions, can directly invoke these functions over the network. This results in the ability to manipulate system configuration or its operating environment without any identity verification.
An attacker can remotely modify system configuration or its operating environment without authentication, which may lead to disruption of time synchronization, takeover of device settings control, and violation of system data integrity and confidentiality.
Patches available from the vendor should be applied in accordance with references. Detailed information about updates is available at the address indicated by Microchip in the official security bulletin. Until patches are applied, it is recommended to limit network access to the TimePictra system through a firewall or network segmentation.
Microchip TimePictra in versions 11.0 to 11.3 SP2 (inclusive).
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMicrochip Timepictra
APPMicrochip11.311.0 – 11.3
Related vulnerabilities
XSS w Microchip TimePictra – wstrzyknięcie złośliwego skryptu
RCE przez buffer overflow w serwerze DHCP Microchip Advanced Software Framework
Nieautoryzowany dostęp w maxView Storage Manager via Redfish Server
Nieautoryzowany dostęp w Microchip maxView Storage Manager przez serwer Redfish
Microchip MPLAB Net — słaba losowość numerów sekwencyjnych TCP (ISN)