CRITICAL🇵🇱 Wersja polska

CVE-2026-2844

CVSS 9.3v4.0pub. 2026-02-28upd. 2026-03-10

Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects TimePictra: from 11.0 through 11.3 SP2.

🤖 AI Analysis
How it works

The vulnerability results from omission of an authentication mechanism for specific critical functions in the TimePictra application. A remote attacker, without the need to possess an account or permissions, can directly invoke these functions over the network. This results in the ability to manipulate system configuration or its operating environment without any identity verification.

Impact

An attacker can remotely modify system configuration or its operating environment without authentication, which may lead to disruption of time synchronization, takeover of device settings control, and violation of system data integrity and confidentiality.

Mitigation & patch

Patches available from the vendor should be applied in accordance with references. Detailed information about updates is available at the address indicated by Microchip in the official security bulletin. Until patches are applied, it is recommended to limit network access to the TimePictra system through a firewall or network segmentation.

Who is affected

Microchip TimePictra in versions 11.0 to 11.3 SP2 (inclusive).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Microchip Timepictra

    APP
    Microchip
    11.311.0 – 11.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-3010CRITICAL9.3PL ✓same product

XSS w Microchip TimePictra – wstrzyknięcie złośliwego skryptu

CVE-2024-7490CRITICAL9.5PL ✓same vendor

RCE przez buffer overflow w serwerze DHCP Microchip Advanced Software Framework

CVE-2023-51438CRITICAL10.0PL ✓same vendor

Nieautoryzowany dostęp w maxView Storage Manager via Redfish Server

CVE-2024-22216CRITICAL10.0PL ✓same vendor

Nieautoryzowany dostęp w Microchip maxView Storage Manager przez serwer Redfish

CVE-2020-27636CRITICAL9.1PL ✓same vendor

Microchip MPLAB Net — słaba losowość numerów sekwencyjnych TCP (ISN)