{
    "data_version": "4.0",
    "data_type": "CVE",
    "data_format": "MITRE",
    "CVE_data_meta": {
        "ID": "CVE-2024-43684",
        "ASSIGNER": "psirt@microchip.com",
        "STATE": "PUBLIC"
    },
    "description": {
        "description_data": [
            {
                "lang": "eng",
                "value": "Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0."
            }
        ]
    },
    "problemtype": {
        "problemtype_data": [
            {
                "description": [
                    {
                        "lang": "eng",
                        "value": "CWE-352 Cross-Site Request Forgery (CSRF)",
                        "cweId": "CWE-352"
                    }
                ]
            }
        ]
    },
    "affects": {
        "vendor": {
            "vendor_data": [
                {
                    "vendor_name": "Microchip",
                    "product": {
                        "product_data": [
                            {
                                "product_name": "TimeProvider 4100",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_affected": "<=",
                                            "version_name": "1.0",
                                            "version_value": "2.4.7"
                                        }
                                    ]
                                }
                            }
                        ]
                    }
                }
            ]
        }
    },
    "references": {
        "reference_data": [
            {
                "url": "https://www.gruppotim.it/it/footer/red-team.html",
                "refsource": "MISC",
                "name": "https://www.gruppotim.it/it/footer/red-team.html"
            },
            {
                "url": "https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities",
                "refsource": "MISC",
                "name": "https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities"
            }
        ]
    },
    "generator": {
        "engine": "Vulnogram 0.2.0"
    },
    "source": {
        "advisory": "PSIRT-87",
        "discovery": "EXTERNAL"
    },
    "work_around": [
        {
            "lang": "en",
            "supportingMedia": [
                {
                    "base64": false,
                    "type": "text/html",
                    "value": "It is important to note that the web interface is only available on a \nphysically separate management port and these vulnerabilities have no \nimpact on the timing service ports. For added security, users have the \noption to disable the web interface, further protecting the device from \npotential web-based exploitations.<br>"
                }
            ],
            "value": "It is important to note that the web interface is only available on a \nphysically separate management port and these vulnerabilities have no \nimpact on the timing service ports. For added security, users have the \noption to disable the web interface, further protecting the device from \npotential web-based exploitations."
        }
    ],
    "credits": [
        {
            "lang": "en",
            "value": "Armando Huesca Prida"
        },
        {
            "lang": "en",
            "value": "Marco Negro"
        },
        {
            "lang": "en",
            "value": "Antonio Carriero"
        },
        {
            "lang": "en",
            "value": "Vito Pistillo"
        },
        {
            "lang": "en",
            "value": "Davide Renna"
        },
        {
            "lang": "en",
            "value": "Manuel Leone"
        },
        {
            "lang": "en",
            "value": "Massimiliano Brolli"
        },
        {
            "lang": "en",
            "value": "TIM Security Red Team Research"
        }
    ]
}