Vulnerabilities > Digi > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-12-10 CVE-2021-37187 Insufficiently Protected Credentials vulnerability in Digi products
An issue was discovered on Digi TransPort devices through 2021-07-21.
network
low complexity
digi CWE-522
6.5
2020-06-02 CVE-2020-10136 Authentication Bypass by Spoofing vulnerability in multiple products
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.
network
low complexity
cisco digi hp treck CWE-290
5.3
2020-02-13 CVE-2020-6973 Cross-site Scripting vulnerability in Digi products
Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2.
network
low complexity
digi CWE-79
6.2
2020-02-12 CVE-2020-6975 Unrestricted Upload of File with Dangerous Type vulnerability in Digi products
Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2.
network
low complexity
digi CWE-434
4.9
2020-02-10 CVE-2020-8822 Cross-site Scripting vulnerability in Digi Transport Wr21 Firmware and Transport Wr44 Firmware
Digi TransPort WR21 5.2.2.3, WR44 5.1.6.4, and WR44v2 5.1.6.9 devices allow stored XSS in the web application.
network
low complexity
digi CWE-79
4.8
2020-01-09 CVE-2019-18859 Cross-site Scripting vulnerability in Digi Anywhereusb/14 Firmware 1.93.21.19
Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.
network
low complexity
digi CWE-79
6.1