CVE-2021-35979
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
08/10/2021
Last modified:
26/05/2023
Description
An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:digi:realport:*:*:*:*:*:linux:*:* | 1.9-40 (including) | |
| cpe:2.3:a:digi:realport:*:*:*:*:*:windows:*:* | 4.8.488.0 (including) | |
| cpe:2.3:o:digi:connectport_ts_8\/16_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:digi:connectport_ts_8\/16:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:digi:connectport_lts_8\/16\/32_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:digi:connectport_lts_8\/16\/32:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:digi:passport_integrated_console_server_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:digi:passport_integrated_console_server:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:digi:cm_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:digi:cm:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:digi:portserver_ts_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:digi:portserver_ts:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:digi:portserver_ts_mei_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:digi:portserver_ts_mei:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:digi:portserver_ts_mei_hardened_firmware:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



