Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.68% | — | Digi RealportDigi Connectport TS 8/16 FirmwareDigi Passport FirmwareDigi Connectport LTS 8/16/32 Firmware+16 | 31/8/2023 | 17/6/2026 | Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment. | |
| Modificada | Crítica (9.8) | 0.69% | — | Digi RealportDigi Connectport TS 8/16 FirmwareDigi Connectport LTS 8/16/32 FirmwareDigi Passport Integrated Console Server Firmware+15 | 8/10/2021 | 17/6/2026 | In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The server will reply with a weakly-hashed version of the server's access password. The… | |
| Modificada | Alta (8.1) | 0.89% | — | Digi RealportDigi Connectport TS 8/16 FirmwareDigi Connectport LTS 8/16/32 FirmwareDigi Passport Integrated Console Server Firmware+14 | 8/10/2021 | 17/6/2026 | An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication. | |
| Modificada | Crítica (9.8) | 1.6% | — | Digi RealportDigi Connectport TS 8/16 FirmwareDigi Connectport LTS 8/16/32 FirmwareDigi Passport Integrated Console Server Firmware+14 | 8/10/2021 | 17/6/2026 | An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP discovery response messages. This could result in arbitrary code execution. |