CVE-2021-35979

An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
VendorProductVersion
digirealport
𝑥
≤ 1.9-40
digirealport
𝑥
≤ 4.8.488.0
digiconnectport_ts_8\/16_firmware
*
digiconnectport_lts_8\/16\/32_firmware
*
digipassport_integrated_console_server_firmware
*
digicm_firmware
*
digiportserver_ts_firmware
*
digiportserver_ts_mei_firmware
*
digiportserver_ts_mei_hardened_firmware
*
digiportserver_ts_m_mei_firmware
*
digi6350-sr_firmware
*
digiportserver_ts_p_mei_firmware
*
digitransport_wr11_xt_firmware
*
digione_iap_family_firmware
*
digione_ia_firmware
*
digiwr31_firmware
*
digiwr44_r_firmware
*
digiconnect_es_firmware
*
digiwr21_firmware
*
𝑥
= Vulnerable software versions