No analysis available yet.
Vendor Workaround
Do not expose the web interface on the separate management port to an untrusted network. For added security, users have the option to disable the web interface, further protecting the device from potential web-based exploitations.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 31 Mar 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 28 Oct 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microchip timeprovider 4100 Firmware
|
|
| CPEs | cpe:2.3:h:microchip:timeprovider_4100:-:*:*:*:*:*:*:* cpe:2.3:o:microchip:timeprovider_4100_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microchip timeprovider 4100 Firmware
|
|
| Metrics |
cvssV3_1
|
Tue, 21 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microchip
Microchip timeprovider 4100 |
|
| Vendors & Products |
Microchip
Microchip timeprovider 4100 |
Mon, 20 Oct 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injection.This issue affects Time Provider 4100: before 2.5. | |
| Title | SQL Injection in web resource | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Microchip
Published:
Updated: 2026-03-31T10:38:57.976Z
Reserved: 2025-05-13T19:24:53.452Z
Link: CVE-2025-47902
Updated: 2025-10-20T20:26:16.067Z
Status : Modified
Published: 2025-10-20T18:15:38.727
Modified: 2026-03-31T11:16:13.087
Link: CVE-2025-47902
No data.
OpenCVE Enrichment
Updated: 2025-10-21T09:39:34Z