Microchip Technology
First CVE: May 16, 2024Active for: 2 years
23
CVEs Published
More CVEs Published than 44% of tracked CNAs
7.7
Avg CVEs / Year
More Avg CVEs / Year than 46% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Microchip Technology as a CNA, 78.3% affect products that Microchip Technology develops as a vendor.
78.3%
21.7%
Self-reported: 18Third-party: 5
Of all the CVEs published that affect products developed by Microchip Technology, 34.0% are self-published by Microchip Technology as a CNA.
34.0%
66.0%
Self-published: 18Published by other CNAs: 35
Trends Over Time
The number and severity of CVEs published by Microchip Technology over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2024
2 years ago
Most Recent CVE
Jun 19, 2026
35 days ago
Top CVEs
All CVEs published by Microchip Technology as a CNA, regardless of affected vendor or product.
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9054HIGH Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip Ti | Oct 4, 2024 | 8.8 | 43 | NO | YES |
CVE-2024-7490CRITICAL Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow.
This vuln | Aug 8, 2024 | 9.8 | 32 | NO | NO |
CVE-2025-9497CRITICAL Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0. | Mar 28, 2026 | 9.8 | 31 | NO | NO |
CVE-2024-43685CRITICAL Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | Oct 4, 2024 | 9.8 | 30 | NO | NO |
CVE-2025-47901HIGH Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affe | Oct 20, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-47900HIGH Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affe | Oct 20, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-47902HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injection.This issue affects Time Prov | Oct 20, 2025 | 8.8 | 28 | NO | NO |
CVE-2024-7801MEDIUM Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules) allows SQL Injection.This issu | Oct 4, 2024 | 6.5 | 28 | NO | YES |
CVE-2024-43687MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site S | Oct 4, 2024 | 6.1 | 27 | NO | YES |
CVE-2026-12620MEDIUM The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints.
This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. | Jun 19, 2026 | 6.5 | 26 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA23 CVEs
52%
35%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.3%)
Network18 (78.3%)
Unknown0 (0.0%)
Physical2 (8.7%)
Adjacent Network2 (8.7%)
Attack Complexity
Low20 (87.0%)
High3 (13.0%)
Unknown0 (0.0%)
User Interaction
None14 (60.9%)
Unknown0 (0.0%)
Required9 (39.1%)
Privileges Required
Low9 (39.1%)
High1 (4.3%)
None13 (56.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
13.0% of CVEs· 99th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Microchip Technology as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Microchip Technology as a CNA — matched by CVE ID, not by organization name.