CVE-2021-38412
Summary
| CVE | CVE-2021-38412 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-17 20:15:00 UTC |
| Updated | 2022-10-27 12:59:00 UTC |
| Description | Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication tokens. This vulnerability could allow an attacker to enable the SNMP service and manipulate the community strings to achieve further control in. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Digi | Portserver Ts 16 | - | All | All | All |
| Operating System | Digi | Portserver Ts 16 Firmware | 82000684 | All | All | All |
| Operating System | Digi | Portserver Ts 16 Firmware | 82000685 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Digi PortServer TS 16 | CISA | MISC | us-cert.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.