CVE-2021-36767
Scores
EPSS
Percentile: 0.0%
CVSS
CVSS Score: 9.8/10
All CVSS Scores
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector Breakdown
CVSS (Common Vulnerability Scoring System) vector provides detailed metrics about vulnerability characteristics
CVSS
Attack Vector
Network (N)
Describes how the vulnerability is exploited
Attack Complexity
Low (L)
Describes the conditions beyond the attacker's control
Privileges Required
None (N)
Describes the level of privileges an attacker must possess
User Interaction
None (N)
Captures the requirement for a human user participation
Scope
Unchanged (U)
Determines if a successful attack impacts components beyond the vulnerable component
Confidentiality Impact
High (H)
Measures the impact to the confidentiality of information
Integrity Impact
High (H)
Measures the impact to integrity of a successfully exploited vulnerability
Availability Impact
High (H)
Measures the impact to the availability of the impacted component
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Vector Breakdown
CVSS (Common Vulnerability Scoring System) vector provides detailed metrics about vulnerability characteristics
CVSS
Attack Vector
Network (N)
Describes how the vulnerability is exploited
Attack Complexity
Low (L)
Describes the conditions beyond the attacker's control
Authentication
None (N)
Describes the level of privileges an attacker must possess
Confidentiality Impact
Partial
Measures the impact to the confidentiality of information
Integrity Impact
Partial
Measures the impact to integrity of a successfully exploited vulnerability
Availability Impact
Partial
Measures the impact to the availability of the impacted component
Description
In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The server will reply with a weakly-hashed version of the server’s access password. The attacker may then crack this hash offline in order to successfully login to the server.
Scaner-VS 7 — a modern vulnerability management solution
Sources
CWEs
Vulnerable Software (19)
Type: Configuration
Vendor: digi
Product: 6350-sr_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:6350-sr_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" ...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:6350-sr_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:6350-sr:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: cm_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:cm_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" },...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:cm_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:cm:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: connect_es_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:connect_es_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:connect_es_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:connect_es:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: connectport_lts_8/16/32_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:connectport_lts_8\\/16\\/32_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], ...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:connectport_lts_8\\/16\\/32_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:connectport_lts_8\\/16\\/32:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: connectport_ts_8/16_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:connectport_ts_8\\/16_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "ope...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:connectport_ts_8\\/16_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:connectport_ts_8\\/16:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: one_ia_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:one_ia_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" ...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:one_ia_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:one_ia:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: one_iap_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:one_iap_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" ...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:one_iap_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:one_iap:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: one_iap_haz_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:one_iap_haz_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "O...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:one_iap_haz_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:one_iap_haz:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: passport_integrated_console_server_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:passport_integrated_console_server_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:passport_integrated_console_server_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:passport_integrated_console_server:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: portserver_ts_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:portserver_ts_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": ...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:portserver_ts_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:portserver_ts:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: portserver_ts_m_mei_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:portserver_ts_m_mei_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "opera...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:portserver_ts_m_mei_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:portserver_ts_m_mei:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: portserver_ts_mei_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:portserver_ts_mei_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operato...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:portserver_ts_mei_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:portserver_ts_mei:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: portserver_ts_mei_hardened_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:portserver_ts_mei_hardened_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], ...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:portserver_ts_mei_hardened_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:portserver_ts_mei_hardened:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: portserver_ts_p_mei_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:portserver_ts_p_mei_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "opera...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:portserver_ts_p_mei_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:portserver_ts_p_mei:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: realport
Operating System: * * *
{ "cpe_match": [ { "cpe23uri": "cpe:2.3:a:digi:realport:*:*:*:*:*:linux:*:*", "versionEndIncluding": "1.9-40", "vulnerable": true }, { "cpe23uri": "cpe:2.3:a:digi...
{ "cpe_match": [ { "cpe23uri": "cpe:2.3:a:digi:realport:*:*:*:*:*:linux:*:*", "versionEndIncluding": "1.9-40", "vulnerable": true }, { "cpe23uri": "cpe:2.3:a:digi:realport:*:*:*:*:*:windows:*:*", "versionEndIncluding": "4.10.490", "vulnerable": true } ], "operator": "OR"}
Source: nvd
Type: Configuration
Vendor: digi
Product: transport_wr11_xt_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:transport_wr11_xt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operato...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:transport_wr11_xt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:transport_wr11_xt:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: wr21_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:wr21_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" ...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:wr21_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:wr21:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: wr31_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:wr31_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" ...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:wr31_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:wr31:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd
Type: Configuration
Vendor: digi
Product: wr44_r_firmware
Operating System: * * *
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:wr44_r_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" ...
{ "children": [ { "cpe_match": [ { "cpe23uri": "cpe:2.3:o:digi:wr44_r_firmware:*:*:*:*:*:*:*:*", "vulnerable": true } ], "operator": "OR" }, { "cpe_match": [ { "cpe23uri": "cpe:2.3:h:digi:wr44_r:-:*:*:*:*:*:*:*" } ], "operator": "OR" } ], "operator": "AND"}
Source: nvd