Digi records
25 published records for vendor digi.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-787 Out-of-bounds Write2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-290 Authentication Bypass by Spoofing1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
25 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-20162Proof of concept | Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privilegedigi · transport lr54 firmware · CWE-20 | Critical9.9 | — | 4.1% | Mar 21, 2019 |
40Plan | CVE-2021-35978No exploit | An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR.digi · transport dr64 firmware · CWE-77 | Critical9.8 | — | 3.6% | Dec 10, 2021 |
39Monitor | CVE-2021-35977No exploit | An issue was discovered in Digi RealPort for Windows through 4.8.488.0.digi · realport · CWE-120 | Critical9.8 | — | 1.6% | Oct 8, 2021 |
39Monitor | CVE-2021-38412No exploit | Digi PortServer TS 16 Improper Authenticationdigi · portserver ts 16 firmware · CWE-287 | Critical9.8 | — | 1.3% | Sep 17, 2021 |
39Monitor | CVE-2022-2634No exploit | Digi ConnectPort X2Ddigi · connectport x2d firmware · CWE-250 | Critical9.8 | — | 1.0% | Aug 10, 2022 |
39Monitor | CVE-2021-36767No exploit | In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making digi · realport · CWE-916 | Critical9.8 | — | 0.7% | Oct 8, 2021 |
35Monitor | CVE-2024-50626No exploit | An issue was discovered in Digi ConnectPort LTS before 1.4.12.digi · connectport lts firmware · CWE-22 | High8.8 | — | 0.5% | Dec 9, 2024 |
35Monitor | CVE-2024-50628No exploit | An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12.digi · connectport lts firmware · CWE-862 | High8.8 | — | 0.5% | Dec 9, 2024 |
35Monitor | CVE-2021-37188No exploit | An issue was discovered on Digi TransPort devices through 2021-07-21.digi · transport dr64 firmware · CWE-345 | High8.8 | — | 0.5% | Dec 10, 2021 |
35Monitor | CVE-2024-50627No exploit | An issue was discovered in Digi ConnectPort LTS before 1.4.12.digi · connectport lts firmware · CWE-552 | High8.8 | — | 0.3% | Dec 9, 2024 |
32Monitor | CVE-2021-35979No exploit | An issue was discovered in Digi RealPort through 4.8.488.0.digi · realport · CWE-306 | High8.1 | — | 0.9% | Oct 8, 2021 |
32Monitor | CVE-2023-4299No exploit | Digi RealPort Protocol Use of Password Hash Instead of Password for Authenticationdigi · realport · CWE-836 | High8.1 | — | 0.7% | Aug 31, 2023 |
32Monitor | CVE-2024-50625No exploit | An issue was discovered in Digi ConnectPort LTS before 1.4.12.digi · connectport lts firmware · CWE-434 | High8.0 | — | 0.3% | Dec 9, 2024 |
31Monitor | CVE-2022-26952No exploit | Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header string when an unaudigi · passport firmware · CWE-787 | High7.5 | — | 2.1% | Apr 5, 2022 |
31Monitor | CVE-2022-26953No exploit | Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow.digi · passport firmware · CWE-787 | High7.5 | — | 1.8% | Apr 5, 2022 |
31Monitor | CVE-2020-12878No exploit | Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses cdigi · connectport x2e firmware · CWE-59 | High7.8 | — | 0.5% | Feb 17, 2021 |
30Monitor | CVE-2020-10136Proof of concept | IP-in-IP protocol allows a remote, unauthenticated attacker to route arbitrary network trafficcisco · nx-os · CWE-290 | Medium5.3 | — | 28.5% | Jun 2, 2020 |
30Monitor | CVE-2017-18868No exploit | Digi XBee 2 devices do not have an effective protection mechanism against remote AT commands, because of issues related to the network stackdigi · xbee 2 firmware · CWE-276 | High7.7 | — | 0.8% | May 21, 2020 |
30Monitor | CVE-2021-37189No exploit | An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4.digi · transport wr11 firmware · CWE-311 | High7.5 | — | 0.6% | Dec 10, 2021 |
26Monitor | CVE-2021-37187No exploit | An issue was discovered on Digi TransPort devices through 2021-07-21.digi · transport dr64 firmware · CWE-522 | Medium6.5 | — | 0.7% | Dec 10, 2021 |
25Monitor | CVE-2019-18859Proof of concept | Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.digi · anywhereusb\/14 firmware · CWE-79 | Medium6.1 | — | 2.4% | Jan 9, 2020 |
24Monitor | CVE-2020-6973No exploit | Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2.digi · connectport lts 32 mei bios · CWE-79 | Medium6.2 | — | 0.8% | Feb 12, 2020 |
21Monitor | CVE-2004-1973Proof of concept | DiGi Web Server allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request that contains a large number digi · www server | Medium5.0 | — | 3.8% | Apr 27, 2004 |
19Monitor | CVE-2020-6975No exploit | Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2.digi · connectport lts 32 mei bios · CWE-434 | Medium4.9 | — | 0.8% | Feb 12, 2020 |
19Monitor | CVE-2020-8822No exploit | Digi TransPort WR21 5.2.2.3, WR44 5.1.6.4, and WR44v2 5.1.6.9 devices allow stored XSS in the web application.digi · transport wr21 firmware · CWE-79 | Medium4.8 | — | 0.6% | Feb 9, 2020 |
- CVE-2018-2016240Plan
Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privilege
CriticalCVSS 9.9Proof of conceptEPSS 4%digi · transport lr54 firmwareMar 21, 2019
- CVE-2021-3597840Plan
An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR.
CriticalCVSS 9.8No exploitEPSS 4%digi · transport dr64 firmwareDec 10, 2021
- CVE-2021-3597739Monitor
An issue was discovered in Digi RealPort for Windows through 4.8.488.0.
CriticalCVSS 9.8No exploitEPSS 2%digi · realportOct 8, 2021
- CVE-2021-3841239Monitor
Digi PortServer TS 16 Improper Authentication
CriticalCVSS 9.8No exploitEPSS 1%digi · portserver ts 16 firmwareSep 17, 2021
- CVE-2022-263439Monitor
Digi ConnectPort X2D
CriticalCVSS 9.8No exploitEPSS 1%digi · connectport x2d firmwareAug 10, 2022
- CVE-2021-3676739Monitor
In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making
CriticalCVSS 9.8No exploitEPSS 1%digi · realportOct 8, 2021
- CVE-2024-5062635Monitor
An issue was discovered in Digi ConnectPort LTS before 1.4.12.
HighCVSS 8.8No exploitEPSS 1%digi · connectport lts firmwareDec 9, 2024
- CVE-2024-5062835Monitor
An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12.
HighCVSS 8.8No exploitEPSS 0%digi · connectport lts firmwareDec 9, 2024
- CVE-2021-3718835Monitor
An issue was discovered on Digi TransPort devices through 2021-07-21.
HighCVSS 8.8No exploitEPSS 0%digi · transport dr64 firmwareDec 10, 2021
- CVE-2024-5062735Monitor
An issue was discovered in Digi ConnectPort LTS before 1.4.12.
HighCVSS 8.8No exploitEPSS 0%digi · connectport lts firmwareDec 9, 2024
- CVE-2021-3597932Monitor
An issue was discovered in Digi RealPort through 4.8.488.0.
HighCVSS 8.1No exploitEPSS 1%digi · realportOct 8, 2021
- CVE-2023-429932Monitor
Digi RealPort Protocol Use of Password Hash Instead of Password for Authentication
HighCVSS 8.1No exploitEPSS 1%digi · realportAug 31, 2023
- CVE-2024-5062532Monitor
An issue was discovered in Digi ConnectPort LTS before 1.4.12.
HighCVSS 8.0No exploitEPSS 0%digi · connectport lts firmwareDec 9, 2024
- CVE-2022-2695231Monitor
Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header string when an unau
HighCVSS 7.5No exploitEPSS 2%digi · passport firmwareApr 5, 2022
- CVE-2022-2695331Monitor
Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow.
HighCVSS 7.5No exploitEPSS 2%digi · passport firmwareApr 5, 2022
- CVE-2020-1287831Monitor
Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses c
HighCVSS 7.8No exploitEPSS 1%digi · connectport x2e firmwareFeb 17, 2021
- CVE-2020-1013630Monitor
IP-in-IP protocol allows a remote, unauthenticated attacker to route arbitrary network traffic
MediumCVSS 5.3Proof of conceptEPSS 29%cisco · nx-osJun 2, 2020
- CVE-2017-1886830Monitor
Digi XBee 2 devices do not have an effective protection mechanism against remote AT commands, because of issues related to the network stack
HighCVSS 7.7No exploitEPSS 1%digi · xbee 2 firmwareMay 21, 2020
- CVE-2021-3718930Monitor
An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4.
HighCVSS 7.5No exploitEPSS 1%digi · transport wr11 firmwareDec 10, 2021
- CVE-2021-3718726Monitor
An issue was discovered on Digi TransPort devices through 2021-07-21.
MediumCVSS 6.5No exploitEPSS 1%digi · transport dr64 firmwareDec 10, 2021
- CVE-2019-1885925Monitor
Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.
MediumCVSS 6.1Proof of conceptEPSS 2%digi · anywhereusb\/14 firmwareJan 9, 2020
- CVE-2020-697324Monitor
Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2.
MediumCVSS 6.2No exploitEPSS 1%digi · connectport lts 32 mei biosFeb 12, 2020
- CVE-2004-197321Monitor
DiGi Web Server allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request that contains a large number
MediumCVSS 5.0Proof of conceptEPSS 4%digi · www serverApr 27, 2004
- CVE-2020-697519Monitor
Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2.
MediumCVSS 4.9No exploitEPSS 1%digi · connectport lts 32 mei biosFeb 12, 2020
- CVE-2020-882219Monitor
Digi TransPort WR21 5.2.2.3, WR44 5.1.6.4, and WR44v2 5.1.6.9 devices allow stored XSS in the web application.
MediumCVSS 4.8No exploitEPSS 1%digi · transport wr21 firmwareFeb 9, 2020