PatchSiren

Microchip CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microchip CVE published 2026-08-24

CVE-2026-18349

The CVE-2026-18349 vulnerability affects Microchip SAMA5D4 devices, allowing Hardware Fault Injection due to improper protection against voltage and clock glitches. This issue has significant implications for organizations utilizing these devices, as it could potentially allow attackers to inject faults into the hardware, leading to a range of possible impacts including denial of service, data corruption, [truncated]

MEDIUM Microchip CVE published 2026-06-19

CVE-2026-12622

The CVE-2026-12622 issue involves an open redirect vulnerability in the password change form submission of the GridTime 3000 GNSS Time Server. This vulnerability affects GridTime 3000 versions from 1.0r0.03 through 1.1r0.0. The CVSS score for this vulnerability is 5.3, classified as MEDIUM severity. Defenders need to assess exposure based on the affected versions and take appropriate measures to mitigate [truncated]

HIGH Microchip CVE published 2026-04-16

CVE-2026-2336

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-16T18:16:44.927Z and has not been modified since then. This CVE-2026-2336 record indicates a privilege escalation vulnerability in Microchip IStaX before version 2026.03. An authenticated low-privileged user can recover a shared per-device cookie secret and forge a new cookie with administrative pri [truncated]

MEDIUM Microchip CVE published 2026-03-28

CVE-2025-9497

The Microchip Time Provider 4100, prior to firmware version 2.5.0, contains a hardcoded credentials vulnerability. This issue allows for malicious manual software updates, potentially leading to unauthorized access and system compromise. Organizations utilizing this product should prioritize updating to version 2.5.0 or later. The vulnerability, tracked as CVE-2025-9497, has been assigned a CVSS score of [truncated]