CVE-2025-47904

Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:microchip:timeprovider_4100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:microchip:timeprovider_4100:-:*:*:*:*:*:*:*

History

03 Mar 2026, 16:18

Type Values Removed Values Added
First Time Microchip timeprovider 4100 Firmware
Microchip
Microchip timeprovider 4100
CPE cpe:2.3:o:microchip:timeprovider_4100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:microchip:timeprovider_4100:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.1
References () https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/timeprovider-4100-unsigned-upgrade-vulnerability - () https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/timeprovider-4100-unsigned-upgrade-vulnerability - Vendor Advisory

24 Feb 2026, 16:24

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-24 16:24

Updated : 2026-03-03 16:18


NVD link : CVE-2025-47904

Mitre link : CVE-2025-47904

CVE.ORG link : CVE-2025-47904


JSON object : View

Products Affected

microchip

  • timeprovider_4100_firmware
  • timeprovider_4100
CWE
CWE-494

Download of Code Without Integrity Check