PT-2021-22116 · Digi · Digi Portserver Ts 16 Rack

Byron Chaney

+1

·

Published

2021-09-17

·

Updated

2022-10-27

·

CVE-2021-38412

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Digi PortServer TS 16 Rack device (affected versions not specified)
Description The issue concerns the Digi PortServer TS 16 Rack device, where properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers do not require authentication or authentication tokens. This could allow an attacker to enable the SNMP service and manipulate the community strings to achieve further control.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2021-38412

Affected Products

Digi Portserver Ts 16 Rack