// For flags

CVE-2021-38412

Digi PortServer TS 16 Improper Authentication

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication tokens. This vulnerability could allow an attacker to enable the SNMP service and manipulate the community strings to achieve further control in.

Las peticiones POST correctamente formateadas a múltiples recursos en los servidores web HTTP y HTTPS del dispositivo Digi PortServer TS 16 Rack no requieren autenticación ni tokens de autenticación. Esta vulnerabilidad podría permitir a un atacante habilitar el servicio SNMP y manipular las cadenas de comunidad para lograr un mayor control en

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-08-10 CVE Reserved
  • 2021-09-17 CVE Published
  • 2024-05-30 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
  • CWE-306: Missing Authentication for Critical Function
CAPEC
References (1)
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Digi
Search vendor "Digi"
Portserver Ts 16 Firmware
Search vendor "Digi" for product "Portserver Ts 16 Firmware"
82000684
Search vendor "Digi" for product "Portserver Ts 16 Firmware" and version "82000684"
-
Affected
in Digi
Search vendor "Digi"
Portserver Ts 16
Search vendor "Digi" for product "Portserver Ts 16"
--
Safe
Digi
Search vendor "Digi"
Portserver Ts 16 Firmware
Search vendor "Digi" for product "Portserver Ts 16 Firmware"
82000685
Search vendor "Digi" for product "Portserver Ts 16 Firmware" and version "82000685"
-
Affected
in Digi
Search vendor "Digi"
Portserver Ts 16
Search vendor "Digi" for product "Portserver Ts 16"
--
Safe