PT-2022-4007 · Digi · Digi Connectport X2E

·

CVE-2022-2634

·

Published

2022-08-04

·

Updated

2022-08-16

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Digi ConnectPort X2D (affected versions not specified)
Description The issue is related to errors in access control, allowing a remote attacker to execute arbitrary code by uploading specially crafted python files. This is due to the lack of device access protections and device permissions when using the web application, which could lead to malicious actions being executed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04840
CVE-2022-2634

Affected Products

Digi Connectport X2E