Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6rh-c775-h225

Опубликовано: 12 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.4

Описание

Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families:

  • Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022

  • Digi One SP/Digi One SP IA/Digi One IA - prior to and including 82000774_Z, build date 10/19/2020

  • Digi One IAP – prior to and including 82000770 Z, build date 10/19/2020

A specially crafted POST request to the device’s web interface may allow an unauthenticated attacker to modify configuration settings.

Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families:

  • Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022

  • Digi One SP/Digi One SP IA/Digi One IA - prior to and including 82000774_Z, build date 10/19/2020

  • Digi One IAP – prior to and including 82000770 Z, build date 10/19/2020

A specially crafted POST request to the device’s web interface may allow an unauthenticated attacker to modify configuration settings.

EPSS

Процентиль: 35%
0.00144
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-287

Связанные уязвимости

nvd
9 месяцев назад

Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022 * Digi One SP/Digi One SP IA/Digi One IA - prior to and including 82000774_Z, build date 10/19/2020 * Digi One IAP – prior to and including 82000770 Z, build date 10/19/2020 A specially crafted POST request to the device’s web interface may allow an unauthenticated attacker to modify configuration settings.

EPSS

Процентиль: 35%
0.00144
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-287