Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families:
* Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022
* Digi One SP/Digi One SP IA/Digi One IA - prior to and including 82000774_Z, build date 10/19/2020
* Digi One IAP – prior to and including 82000770 Z, build date 10/19/2020
A specially crafted POST request to the device’s web interface may allow an unauthenticated attacker to modify configuration settings.
CVSS
No CVSS.
References
Configurations
No configuration.
History
12 May 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-12 21:15
Updated : 2025-05-12 21:15
NVD link : CVE-2025-3659
Mitre link : CVE-2025-3659
CVE.ORG link : CVE-2025-3659
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication