CVE-2021-37187

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
10/12/2021
Last modified:
14/12/2021

Description

An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may read a password file (with reversible passwords) from the device, which allows decoding of other users' passwords.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:digi:transport_dr64_firmware:*:*:*:*:*:*:*:* 5.2.4.9 (including)
cpe:2.3:h:digi:transport_dr64:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:transport_dr64_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:digi:transport_sr44:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:transport_vc74_firmware:*:*:*:*:*:*:*:* 5.2.4.9 (including)
cpe:2.3:h:digi:transport_vc74:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:transport_wr11_firmware:*:*:*:*:*:*:*:* 8.2.1.3 (including)
cpe:2.3:h:digi:transport_wr11:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:transport_wr11_xt_firmware:*:*:*:*:*:*:*:* 8.2.1.3 (including)
cpe:2.3:h:digi:transport_wr11_xt:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:transport_wr21_firmware:*:*:*:*:*:*:*:* 8.2.1.3 (including)
cpe:2.3:h:digi:transport_wr21:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:transport_wr31_firmware:*:*:*:*:*:*:*:* 8.2.1.3 (including)
cpe:2.3:h:digi:transport_wr31:-:*:*:*:*:*:*:*
cpe:2.3:o:digi:transport_wr41_firmware:*:*:*:*:*:*:*:* 5.0.0.0 (including) 5.2.4.6 (including)