VendorsDigiconnect_esany version
Vulnerabilities

Digi Connect ES any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-35977
An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP discovery response messages. This could result in arbitrary code execution.
Published 2021-10-08 · Modified
9.8EPSS 0.016
CVE-2021-36767
In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The server will reply with a weakly-hashed version of the server's access password. The attacker may then crack this hash offline in order to successfully login to the server.
Published 2021-10-08 · Modified
9.8EPSS 0.007
CVE-2023-4299
Digi RealPort Protocol Use of Password Hash Instead of Password for Authentication
Published 2023-08-31 · Modified
9.0EPSS 0.007
CVE-2021-35979
An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication.
Published 2021-10-08 · Modified
8.1EPSS 0.009