CVE-2023-4299
Summary
| CVE | CVE-2023-4299 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-31 21:15:00 UTC |
| Updated | 2023-09-06 20:13:00 UTC |
| Description | Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment. |
Risk And Classification
Problem Types: CWE-836
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Digi | Cm | - | All | All | All |
| Operating System | Digi | Cm Firmware | - | All | All | All |
| Hardware | Digi | Connectport Lts 8/16/32 | - | All | All | All |
| Operating System | Digi | Connectport Lts 8/16/32 Firmware | All | All | All | All |
| Hardware | Digi | Connectport Ts 8/16 | - | All | All | All |
| Operating System | Digi | Connectport Ts 8/16 Firmware | All | All | All | All |
| Hardware | Digi | Connect Es | - | All | All | All |
| Operating System | Digi | Connect Es Firmware | All | All | All | All |
| Hardware | Digi | Connect Sp | - | All | All | All |
| Operating System | Digi | Connect Sp Firmware | - | All | All | All |
| Hardware | Digi | One Ia | - | All | All | All |
| Hardware | Digi | One Iap | - | All | All | All |
| Operating System | Digi | One Iap Firmware | - | All | All | All |
| Operating System | Digi | One Ia Firmware | - | All | All | All |
| Hardware | Digi | One Sp | - | All | All | All |
| Operating System | Digi | One Sp Firmware | - | All | All | All |
| Hardware | Digi | One Sp Ia | - | All | All | All |
| Operating System | Digi | One Sp Ia Firmware | - | All | All | All |
| Hardware | Digi | Passport | - | All | All | All |
| Operating System | Digi | Passport Firmware | - | All | All | All |
| Hardware | Digi | Portserver Ts | - | All | All | All |
| Operating System | Digi | Portserver Ts Firmware | - | All | All | All |
| Hardware | Digi | Portserver Ts Mei | - | All | All | All |
| Operating System | Digi | Portserver Ts Mei Firmware | - | All | All | All |
| Hardware | Digi | Portserver Ts Mei Hardened | - | All | All | All |
| Operating System | Digi | Portserver Ts Mei Hardened Firmware | - | All | All | All |
| Hardware | Digi | Portserver Ts M Mei | - | All | All | All |
| Operating System | Digi | Portserver Ts M Mei Firmware | - | All | All | All |
| Hardware | Digi | Portserver Ts P Mei | - | All | All | All |
| Operating System | Digi | Portserver Ts P Mei Firmware | - | All | All | All |
| Application | Digi | Realport | All | All | All | All |
| Application | Digi | Realport | All | All | All | All |
| Hardware | Digi | Transport Wr11 Xt | - | All | All | All |
| Operating System | Digi | Transport Wr11 Xt Firmware | - | All | All | All |
| Hardware | Digi | Wr21 | - | All | All | All |
| Operating System | Digi | Wr21 Firmware | - | All | All | All |
| Hardware | Digi | Wr31 | - | All | All | All |
| Operating System | Digi | Wr31 Firmware | - | All | All | All |
| Hardware | Digi | Wr44 R | - | All | All | All |
| Operating System | Digi | Wr44 R Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Digi RealPort Protocol | CISA | MISC | www.cisa.gov | |
| www.digi.com/getattachment/resources/security/alerts/realport-cves/Dragos-... | MISC | www.digi.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.