Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Improper authentication handling for Digi PortServer TS; Digi One SP, SP IA, IA; Digi One IAP
Vulnerability Description
Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022 * Digi One SP/Digi One SP IA/Digi One IA - prior to and including 82000774_Z, build date 10/19/2020 * Digi One IAP – prior to and including 82000770 Z, build date 10/19/2020 A specially crafted POST request to the device’s web interface may allow an unauthenticated attacker to modify configuration settings.
CVSS Information
N/A
Vulnerability Type
认证机制不恰当
Vulnerability Title
Digi多款产品 安全漏洞
Vulnerability Description
Digi PortServer TS等都是Digi公司的产品。Digi PortServer TS是Digi One SP是一款工业级串口设备服务器。Digi One IAP是一个工业自动化协议转换器,专为PLC和SCADA系统设计的智能串口服务器。 Digi多款产品存在安全漏洞,该漏洞源于HTTP POST请求中身份验证处理不当,可能导致修改配置设置。以下产品和版本受到影响:Digi PortServer TS 82000747_AA及之前版本、Digi One SP/Digi One SP IA/Di
CVSS Information
N/A
Vulnerability Type
N/A