CVE Tools

Digi

14 CVEs tracked since 2020. Since Feb 2020, none of them reached CISA KEV.

Digi CVEs per month

Feb 2020 to Dec 2024. Point at a month, or focus the strip and use the arrow keys.
Digi CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-0230
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-1030
2021-11null or fewer
2021-1240
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-1240

Products

The products that kept showing up in Digi's monthly top three, with their CVEs summed over those months.

  1. Transport WR21 Firmware52 months
  2. Connectport Lts Firmware41 month
  3. Transport WR31 Firmware41 month
  4. Transport WR44 Firmware41 month
  5. Connectport Ts 8\/16 Firmware31 month
  6. One Ia Firmware31 month
  7. WR44 R Firmware31 month
  8. Connectport Lts 32 Mei Bios21 month
  9. Connectport Lts 32 Mei Firmware21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Digi.

  1. CVE-2024-50628An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12. It allows an attacker on the local area network to achieve unauthorized manipulation of resources, which may lead ...8.8
  2. CVE-2024-50627An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file upload feature. It allows an attacker on the local area network (with specific...8.8
  3. CVE-2024-50626An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This allows an attacker on the local area network to manipulate URLs to include t...8.8
  4. CVE-2024-50625An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation of file paths via POST requests. This can lead to...8.0
  5. CVE-2023-4299Digi RealPort Protocol Use of Password Hash Instead of Password for Authentication9.0
  6. CVE-2022-2634Digi ConnectPort X2D10.0
  7. CVE-2022-26952Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header string when an unauthenticated user is redirected to the authentication page.7.5
  8. CVE-2022-26953Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow. An attacker can supply a string in the page parameter for reboot.asp endpoint, allowing him to force an overflow when the st...7.5
  9. CVE-2021-37189An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send th...7.5
  10. CVE-2021-37188An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firmware (because the bootloader does not verify that it is authentic), changing ...8.8
  11. CVE-2021-37187An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may read a password file (with reversible passwords) from the device, which allows decoding of other ...6.5
  12. CVE-2021-35978An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges. This allows an attacker (with knowledge of the ...9.8
  13. CVE-2021-36767In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unaut...9.8
  14. CVE-2021-35979An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication.8.1
  15. CVE-2021-35977An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP discovery response messages. This could result in arbitrary code execution.9.8

The record

Peak rank
#105 in Feb 2020
Busiest month shown
Dec 2021, 4 CVEs
Months with a KEV entry
0 since Feb 2020
Monthly snapshots
4 since 2020
Digi's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store