The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints.

This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.

Project Subscriptions

Vendors Products
Microchip Subscribe
Gridtime 3000 Subscribe
Advisories

No advisories yet.

Fixes

Solution

Upgrade GridTime 3000 GNSS Time Server to the latest firmware. As of the firmware release 1.2r0.0, Access tokens have been removed from URL parameters on affected endpoints.


Workaround

No workaround given by the vendor.

History

Mon, 22 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 21 Jun 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Microchip
Microchip gridtime 3000
Vendors & Products Microchip
Microchip gridtime 3000

Fri, 19 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Description The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.
Title Access Token Exposure in URL Parameters in GridTime™ 3000 GNSS Time Server
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:A'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Microchip

Published:

Updated: 2026-06-29T05:22:09.732Z

Reserved: 2026-06-18T14:15:03.036Z

Link: CVE-2026-12620

cve-icon Vulnrichment

Updated: 2026-06-22T16:52:53.157Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-20T22:35:30Z

Weaknesses