Skip to content
Noroxi

Digi records

25 published records for vendor digi.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

25 records
  • Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privilege

    CriticalCVSS 9.9Proof of conceptEPSS 4%

    digi · transport lr54 firmwareMar 21, 2019

  • An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR.

    CriticalCVSS 9.8No exploitEPSS 4%

    digi · transport dr64 firmwareDec 10, 2021

  • An issue was discovered in Digi RealPort for Windows through 4.8.488.0.

    CriticalCVSS 9.8No exploitEPSS 2%

    digi · realportOct 8, 2021

  • Digi PortServer TS 16 Improper Authentication

    CriticalCVSS 9.8No exploitEPSS 1%

    digi · portserver ts 16 firmwareSep 17, 2021

  • CVE-2022-2634
    39Monitor

    Digi ConnectPort X2D

    CriticalCVSS 9.8No exploitEPSS 1%

    digi · connectport x2d firmwareAug 10, 2022

  • In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making

    CriticalCVSS 9.8No exploitEPSS 1%

    digi · realportOct 8, 2021

  • An issue was discovered in Digi ConnectPort LTS before 1.4.12.

    HighCVSS 8.8No exploitEPSS 1%

    digi · connectport lts firmwareDec 9, 2024

  • An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12.

    HighCVSS 8.8No exploitEPSS 0%

    digi · connectport lts firmwareDec 9, 2024

  • An issue was discovered on Digi TransPort devices through 2021-07-21.

    HighCVSS 8.8No exploitEPSS 0%

    digi · transport dr64 firmwareDec 10, 2021

  • An issue was discovered in Digi ConnectPort LTS before 1.4.12.

    HighCVSS 8.8No exploitEPSS 0%

    digi · connectport lts firmwareDec 9, 2024

  • An issue was discovered in Digi RealPort through 4.8.488.0.

    HighCVSS 8.1No exploitEPSS 1%

    digi · realportOct 8, 2021

  • CVE-2023-4299
    32Monitor

    Digi RealPort Protocol Use of Password Hash Instead of Password for Authentication

    HighCVSS 8.1No exploitEPSS 1%

    digi · realportAug 31, 2023

  • An issue was discovered in Digi ConnectPort LTS before 1.4.12.

    HighCVSS 8.0No exploitEPSS 0%

    digi · connectport lts firmwareDec 9, 2024

  • Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header string when an unau

    HighCVSS 7.5No exploitEPSS 2%

    digi · passport firmwareApr 5, 2022

  • Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow.

    HighCVSS 7.5No exploitEPSS 2%

    digi · passport firmwareApr 5, 2022

  • Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses c

    HighCVSS 7.8No exploitEPSS 1%

    digi · connectport x2e firmwareFeb 17, 2021

  • IP-in-IP protocol allows a remote, unauthenticated attacker to route arbitrary network traffic

    MediumCVSS 5.3Proof of conceptEPSS 29%

    cisco · nx-osJun 2, 2020

  • Digi XBee 2 devices do not have an effective protection mechanism against remote AT commands, because of issues related to the network stack

    HighCVSS 7.7No exploitEPSS 1%

    digi · xbee 2 firmwareMay 21, 2020

  • An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4.

    HighCVSS 7.5No exploitEPSS 1%

    digi · transport wr11 firmwareDec 10, 2021

  • An issue was discovered on Digi TransPort devices through 2021-07-21.

    MediumCVSS 6.5No exploitEPSS 1%

    digi · transport dr64 firmwareDec 10, 2021

  • Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.

    MediumCVSS 6.1Proof of conceptEPSS 2%

    digi · anywhereusb\/14 firmwareJan 9, 2020

  • CVE-2020-6973
    24Monitor

    Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2.

    MediumCVSS 6.2No exploitEPSS 1%

    digi · connectport lts 32 mei biosFeb 12, 2020

  • CVE-2004-1973
    21Monitor

    DiGi Web Server allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request that contains a large number

    MediumCVSS 5.0Proof of conceptEPSS 4%

    digi · www serverApr 27, 2004

  • CVE-2020-6975
    19Monitor

    Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2.

    MediumCVSS 4.9No exploitEPSS 1%

    digi · connectport lts 32 mei biosFeb 12, 2020

  • CVE-2020-8822
    19Monitor

    Digi TransPort WR21 5.2.2.3, WR44 5.1.6.4, and WR44v2 5.1.6.9 devices allow stored XSS in the web application.

    MediumCVSS 4.8No exploitEPSS 1%

    digi · transport wr21 firmwareFeb 9, 2020