Executive brief
The Microchip Time Provider 4100 is a critical network timing appliance used to synchronize clocks and maintain accurate time across infrastructure and enterprise networks. An attacker with network access can exploit hard-coded credentials in the device's software update mechanism to perform unauthorized firmware updates, potentially compromising time synchronization, introducing timing attacks, or establishing a persistent foothold in sensitive network environments.
Technical details
This vulnerability involves the use of hard-coded credentials embedded in the Time Provider 4100 firmware that protect the software update/upgrade mechanism. An attacker with network access to the device can use these credentials to bypass authentication controls and initiate malicious firmware updates without proper authorization. The vulnerability allows complete compromise of the device and may enable arbitrary code execution, denial of service, or persistent compromise. Patches are available in version 2.5.0 and later; devices running versions before 2.5.0 are affected and should be updated immediately.
Affected products
- Microchip Time Provider 4100 before 2.5.0
Timeline
- 2026-03-28: disclosed
- 2025-02-05: patched: Fix available in version 2.5.0