PT-2022-4007 · Digi · Digi Connectport X2E

Aarón Flecha

·

Published

2022-08-04

·

Updated

2022-08-16

·

CVE-2022-2634

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Digi ConnectPort X2D (affected versions not specified)
Description The issue is related to errors in access control, allowing a remote attacker to execute arbitrary code by uploading specially crafted python files. This is due to the lack of device access protections and device permissions when using the web application, which could lead to malicious actions being executed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2022-04840
CVE-2022-2634

Affected Products

Digi Connectport X2E