Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.

Subscriptions

Vendors Products
Microchip Subscribe
Timeprovider 4100 Subscribe
Timeprovider 4100 Firmware Subscribe

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Upgrades are only available on a separate management port which should not be connected to an untrusted network. ACLs are available to further restrict access to only trusted addresses.

History

Tue, 03 Mar 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Microchip timeprovider 4100 Firmware
CPEs cpe:2.3:h:microchip:timeprovider_4100:-:*:*:*:*:*:*:*
cpe:2.3:o:microchip:timeprovider_4100_firmware:*:*:*:*:*:*:*:*
Vendors & Products Microchip timeprovider 4100 Firmware
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N'}


Thu, 26 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Feb 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Microchip
Microchip timeprovider 4100
Vendors & Products Microchip
Microchip timeprovider 4100

Tue, 24 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Description Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.
Title Unsigned upgrade package
Weaknesses CWE-494
References
Metrics cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Microchip

Published:

Updated: 2026-02-26T19:53:24.404Z

Reserved: 2025-05-13T19:24:53.452Z

Link: CVE-2025-47904

cve-icon Vulnrichment

Updated: 2026-02-26T19:52:15.134Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-24T16:24:06.680

Modified: 2026-03-03T16:18:42.423

Link: CVE-2025-47904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-25T11:38:45Z

Weaknesses