CRITICAL🇵🇱 Wersja polska

CVE-2021-38412

CVSS 9.6v3.1pub. 2021-09-17upd. 2024-11-21

Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication tokens. This vulnerability could allow an attacker to enable the SNMP service and manipulate the community strings to achieve further control in.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
  • Digi Portserver Ts 16

    HW
    Digi
    all versions
  • Digi Portserver Ts 16 Firmware

    OS
    Digi
    8200068482000685
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2023-4299CRITICAL9.0PL ✓same vendor

Digi RealPort Protocol — podatność na atak replay umożliwiająca ominięcie uwierzytelnienia

CVE-2022-2634CRITICAL10.0PL ✓same vendor

Brak kontroli dostępu w Digi Connectport X2D umożliwia RCE przez upload plików Python

CVE-2021-35978CRITICAL9.8PL ✓same vendor

RCE z uprawnieniami SUPER w protokole ZING urządzeń Digi TransPort

CVE-2021-35977CRITICAL9.8PL ✓same vendor

Buffer overflow w Digi RealPort — wykonanie dowolnego kodu przez ADDP

CVE-2021-36767CRITICAL9.8PL ✓same vendor

Digi RealPort — słabe haszowanie hasła umożliwia nieautoryzowany dostęp