Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header string when an unauthenticated user is redirected to the authentication page.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HDigi Passport
HWDigiall versionsDigi Passport Firmware
OSDigi≤ 1.5.1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References
Related vulnerabilities
CVE-2023-4299CRITICAL9.0PL ✓same product
Digi RealPort Protocol — podatność na atak replay umożliwiająca ominięcie uwierzytelnienia
CVE-2022-26953HIGH7.5same product
Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow. An attacker can supply a string in th...
CVE-2022-2634CRITICAL10.0PL ✓same vendor
Brak kontroli dostępu w Digi Connectport X2D umożliwia RCE przez upload plików Python
CVE-2021-35978CRITICAL9.8PL ✓same vendor
RCE z uprawnieniami SUPER w protokole ZING urządzeń Digi TransPort
CVE-2021-35977CRITICAL9.8PL ✓same vendor
Buffer overflow w Digi RealPort — wykonanie dowolnego kodu przez ADDP