{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-12619",
        "assignerOrgId": "dc3f6da9-85b5-4a73-84a2-2ec90b40fca5",
        "state": "PUBLISHED",
        "assignerShortName": "Microchip",
        "dateReserved": "2026-06-18T14:14:48.848Z",
        "datePublished": "2026-06-19T15:40:50.609Z",
        "dateUpdated": "2026-06-29T05:22:52.398Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "dc3f6da9-85b5-4a73-84a2-2ec90b40fca5",
                "shortName": "Microchip",
                "dateUpdated": "2026-06-29T05:22:52.398Z"
            },
            "title": "GridTime™ 3000 GNSS Time Server CSRF to XSS",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-79",
                            "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-63",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-63 Cross-Site Scripting (XSS)"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Microchip",
                    "product": "GridTime 3000",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "1.0r0.03",
                            "lessThanOrEqual": "1.1r0.0",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Site Scripting (XSS).\n\nThis issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Site Scripting (XSS).<p>This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/gridtime-3000-gnss-time-server-csrf-to-xss",
                    "tags": [
                        "vendor-advisory"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "privilegesRequired": "LOW",
                        "userInteraction": "PASSIVE",
                        "vulnConfidentialityImpact": "NONE",
                        "subConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "LOW",
                        "subIntegrityImpact": "NONE",
                        "vulnAvailabilityImpact": "LOW",
                        "subAvailabilityImpact": "NONE",
                        "exploitMaturity": "ATTACKED",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "NOT_DEFINED",
                        "version": "4.0",
                        "baseSeverity": "MEDIUM",
                        "baseScore": 5.1,
                        "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:A"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "Upgrade GridTime 3000 GNSS Time Server to the latest firmware.\n\n\n\n\n\nAs of the firmware release 1.2r0.0, CSRF protections and parameter \nsanitization have been improved to not allow execution of arbitrary \nqueries.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<div>\nUpgrade GridTime 3000 GNSS Time Server to the latest firmware.</div><div><br></div><div>\nAs of the firmware release 1.2r0.0, CSRF protections and parameter \nsanitization have been improved to not allow execution of arbitrary \nqueries.</div>"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Leo Angelo Diamat (Bastion Security Group)",
                    "type": "reporter"
                }
            ],
            "source": {
                "advisory": "PSIRT-144",
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.2"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-06-22T16:44:48.323337Z",
                                "id": "CVE-2026-12619",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-06-22T17:14:41.684Z"
                }
            }
        ]
    }
}