Executive brief
The Microchip GridTime 3000, a high-precision time server used in critical infrastructure, contains a security flaw in its password reset interface. An attacker with low-level access could inject malicious scripts into the web management console. This could lead to unauthorized actions being performed in the context of other users' sessions, potentially compromising the management of the timing device.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the password reset form of the Microchip GridTime 3000 GNSS Time Server. The vulnerability stems from improper neutralization of user-supplied input during web page generation. An attacker with low privileges (PR:L) can exploit this over the network to execute arbitrary JavaScript in the context of a victim's browser session. The issue affects firmware versions from 1.0r0.03 through 1.1r0.0 and is addressed in version 1.2r0.0.
Affected products
- Microchip Technology GridTime 3000 GNSS Time Server 1.0r0.03 to 1.1r0.0
Timeline
- 2026-06-19: disclosed
- 2026-06-19: advisory