CVE-2022-2634
Published on: Not Yet Published
Last Modified on: 08/16/2022 11:57:00 AM UTC
Certain versions of Connectport X2d from Digi contain the following vulnerability:
An attacker may be able to execute malicious actions due to the lack of device access protections and device permissions when using the web application. This could lead to uploading python files which can be later executed.
- CVE-2022-2634 has been assigned by
ics-[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
Digi - ConnectPort X2D version = manufactured prior to 01/2020
Vulnerability Patch/Work Around
- Digi International indicated this vulnerability does not exist in ConnectPort gateways manufactured after January 2020. It is recommended to contact Digi International support for assistance with impacted devices manufactured prior to January 2020.
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Digi ConnectPort X2D | CISA | www.cisa.gov text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Digi | Connectport X2d | - | All | All | All |
Operating System | Digi | Connectport X2d Firmware | All | All | All | All |
- cpe:2.3:h:digi:connectport_x2d:-:*:*:*:*:*:*:*:
- cpe:2.3:o:digi:connectport_x2d_firmware:*:*:*:*:*:*:*:*:
Discovery Credit
Aarón Flecha of S21sec reported this vulnerability to CISA.
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-2634 : An attacker may be able to execute malicious actions due to the lack of device access protections a… twitter.com/i/web/status/1… | 2022-08-10 20:39:38 |
![]() |
Python - CVE-2022-2634: cisa.gov/uscert/ics/adv… | 2022-08-10 23:00:06 |
![]() |
CVE-2022-2634 | 2022-08-10 21:38:21 |