CVE-2021-36767
Summary
| CVE | CVE-2021-36767 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-08 15:15:00 UTC |
| Updated | 2023-09-25 02:30:00 UTC |
| Description | In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The server will reply with a weakly-hashed version of the server's access password. The attacker may then crack this hash offline in order to successfully login to the server. |
Risk And Classification
Problem Types: CWE-916
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Digi | 6350-sr | - | All | All | All |
| Operating System | Digi | 6350-sr Firmware | All | All | All | All |
| Hardware | Digi | Cm | - | All | All | All |
| Operating System | Digi | Cm Firmware | All | All | All | All |
| Hardware | Digi | Connectcore 8x | - | All | All | All |
| Operating System | Digi | Connectcore 8x Firmware | All | All | All | All |
| Hardware | Digi | Connectcore 8x Sbc Pro | - | All | All | All |
| Operating System | Digi | Connectcore 8x Sbc Pro Firmware | All | All | All | All |
| Hardware | Digi | Connectcore 8x Som Dualxz | - | All | All | All |
| Operating System | Digi | Connectcore 8x Som Dualxz Firmware | All | All | All | All |
| Hardware | Digi | Connectcore 8x Som Quadxplus | - | All | All | All |
| Operating System | Digi | Connectcore 8x Som Quadxplus Firmware | All | All | All | All |
| Hardware | Digi | Connectport Lts 8/16/32 | - | All | All | All |
| Operating System | Digi | Connectport Lts 8/16/32 Firmware | All | All | All | All |
| Hardware | Digi | Connectport Ts 8/16 | - | All | All | All |
| Operating System | Digi | Connectport Ts 8/16 Firmware | All | All | All | All |
| Hardware | Digi | Connect Es | - | All | All | All |
| Operating System | Digi | Connect Es Firmware | All | All | All | All |
| Hardware | Digi | One Ia | - | All | All | All |
| Hardware | Digi | One Iap | - | All | All | All |
| Operating System | Digi | One Iap Firmware | All | All | All | All |
| Hardware | Digi | One Iap Haz | - | All | All | All |
| Operating System | Digi | One Iap Haz Firmware | All | All | All | All |
| Operating System | Digi | One Ia Firmware | All | All | All | All |
| Hardware | Digi | Passport Integrated Console Server | - | All | All | All |
| Operating System | Digi | Passport Integrated Console Server Firmware | All | All | All | All |
| Hardware | Digi | Portserver Ts | - | All | All | All |
| Operating System | Digi | Portserver Ts Firmware | All | All | All | All |
| Hardware | Digi | Portserver Ts Mei | - | All | All | All |
| Operating System | Digi | Portserver Ts Mei Firmware | All | All | All | All |
| Hardware | Digi | Portserver Ts Mei Hardened | - | All | All | All |
| Operating System | Digi | Portserver Ts Mei Hardened Firmware | All | All | All | All |
| Hardware | Digi | Portserver Ts M Mei | - | All | All | All |
| Operating System | Digi | Portserver Ts M Mei Firmware | All | All | All | All |
| Hardware | Digi | Portserver Ts P Mei | - | All | All | All |
| Operating System | Digi | Portserver Ts P Mei Firmware | All | All | All | All |
| Application | Digi | Realport | All | All | All | All |
| Application | Digi | Realport | All | All | All | All |
| Application | Digi | Realport | All | All | All | All |
| Hardware | Digi | Transport Wr11 Xt | - | All | All | All |
| Operating System | Digi | Transport Wr11 Xt Firmware | All | All | All | All |
| Hardware | Digi | Wr21 | - | All | All | All |
| Operating System | Digi | Wr21 Firmware | All | All | All | All |
| Hardware | Digi | Wr31 | - | All | All | All |
| Operating System | Digi | Wr31 Firmware | All | All | All | All |
| Hardware | Digi | Wr44 R | - | All | All | All |
| Operating System | Digi | Wr44 R Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| raw.githubusercontent.com/reidmefirst/vuln-disclosure/main/2021-02.txt | MISC | raw.githubusercontent.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.