Executive brief
Microchip GridTime 3000 is a high-precision time server used to synchronize industrial and power grid networks. A security vulnerability in its web management interface could allow an attacker to execute malicious scripts in the browser of a logged-in administrator. This could lead to unauthorized configuration changes or the disruption of time synchronization services critical to infrastructure operations.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Microchip GridTime 3000 GNSS Time Server due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is reachable over the network and requires low-privileged authentication and some level of user interaction (such as a victim clicking a malicious link). An attacker can exploit this to execute arbitrary JavaScript in the context of the victim's session, which may be leveraged alongside other web vulnerabilities like CSRF to modify device settings or impact availability. The issue affects firmware versions 1.0r0.03 through 1.1r0.0.
Affected products
- Microchip GridTime 3000 1.0r0.03 through 1.1r0.0
Timeline
- 2026-06-19: disclosed
- 2026-06-19: advisory