CVE-2021-35979

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
08/10/2021
Last modified:
26/05/2023

Description

An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:digi:realport:*:*:*:*:*:linux:*:* 1.9-40 (including)
cpe:2.3:a:digi:realport:*:*:*:*:*:windows:*:* 4.8.488.0 (including)
cpe:2.3:o:digi:connectport_ts_8\/16_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:digi:connectport_ts_8\/16:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:connectport_lts_8\/16\/32_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:digi:connectport_lts_8\/16\/32:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:passport_integrated_console_server_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:digi:passport_integrated_console_server:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:cm_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:digi:cm:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:portserver_ts_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:digi:portserver_ts:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:portserver_ts_mei_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:digi:portserver_ts_mei:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:portserver_ts_mei_hardened_firmware:*:*:*:*:*:*:*:*