Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication tokens. This vulnerability could allow an attacker to enable the SNMP service and manipulate the community strings to achieve further control in.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:LDigi Portserver Ts 16
HWDigiall versionsDigi Portserver Ts 16 Firmware
OSDigi8200068482000685
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
Related vulnerabilities
CVE-2023-4299CRITICAL9.0PL ✓same vendor
Digi RealPort Protocol — podatność na atak replay umożliwiająca ominięcie uwierzytelnienia
CVE-2022-2634CRITICAL10.0PL ✓same vendor
Brak kontroli dostępu w Digi Connectport X2D umożliwia RCE przez upload plików Python
CVE-2021-35978CRITICAL9.8PL ✓same vendor
RCE z uprawnieniami SUPER w protokole ZING urządzeń Digi TransPort
CVE-2021-35977CRITICAL9.8PL ✓same vendor
Buffer overflow w Digi RealPort — wykonanie dowolnego kodu przez ADDP
CVE-2021-36767CRITICAL9.8PL ✓same vendor
Digi RealPort — słabe haszowanie hasła umożliwia nieautoryzowany dostęp