Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-38412

Опубликовано: 17 сент. 2021
Источник: nvd
CVSS3: 9.6
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication tokens. This vulnerability could allow an attacker to enable the SNMP service and manipulate the community strings to achieve further control in.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:digi:portserver_ts_16_firmware:82000684:*:*:*:*:*:*:*
cpe:2.3:o:digi:portserver_ts_16_firmware:82000685:*:*:*:*:*:*:*
cpe:2.3:h:digi:portserver_ts_16:-:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00156
Низкий

9.6 Critical

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287
CWE-306

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication tokens. This vulnerability could allow an attacker to enable the SNMP service and manipulate the community strings to achieve further control in.

EPSS

Процентиль: 37%
0.00156
Низкий

9.6 Critical

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287
CWE-306