Microchip TimePictra Missing Authentication Vulnerability in Web Application Allowing Unauthenticated Access to Critical Functions
Vulnerability
A vulnerability in the Microchip TimePictra web application, affecting versions 11.0 through 11.3 SP2, allows missing authentication for critical functions. This issue enables unauthorized access to endpoints for creating and deleting network elements, potentially leading to unauthorized manipulation of network configurations.
Impact
Exploitation of this vulnerability could allow an attacker to create or delete tracked network elements within the TimePictra application.
Remediation
It is recommended to control access to the TimePictra web application. Microchip plans to address this vulnerability in a future release.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
