CVE-2024-9054
CVSS v3
8.8
HIGH
EPSS Score
15.6 %
exploit probability, as of 2026-10-05
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.
Technical details
- Published
- 2024-10-04
- Exploit-DB
- EDB-52119
Frequently asked questions
What is CVE-2024-9054?
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.
Is CVE-2024-9054 actively exploited?
Active exploitation of CVE-2024-9054 has not been confirmed. Its EPSS score was 15.6% on 2026-10-05, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2024-9054?
CVE-2024-9054 has a CVSS v3 base score of 8.8 (HIGH severity).
Is CVE-2024-9054 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 50 free checks/month · Free API key
Other 2024 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).