Use of Password Hash Instead of Password for Authentication in Digi International Inc. products - CVE-2023-4299

 

Use of Password Hash Instead of Password for Authentication in Digi International Inc. products - CVE-2023-4299

Published: September 4, 2023


Vulnerability identifier: #VU80325
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-4299
CWE-ID: CWE-836
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to use of password hash instead of password for authentication in Digi RealPort Protocol. A remote attacker can perform a replay attack and bypass authentication to access connected equipment.


Affected software

​Digi PortServer TS P MEI
​Digi Connect SP
​Digi WR21
​Digi WR44 R
​Digi WR11 XT
​Digi WR31
​Digi One SP
​Digi One SP IA
​Digi One IA
​Digi One IAP Family
Digi RealPort for Windows
​Digi PortServer TS M MEI
​Digi PortServer TS MEI Hardened
​Digi PortServer TS MEI
​Digi PortServer TS
​Digi CM Console Server
​Digi Passport Console Server
​Digi RealPort for Linux
​Digi ConnectPort LTS 8/16/32
​Digi ConnectPort TS 8/16
​Digi Connect ES

How to mitigate CVE-2023-4299

Install updates from vendor's website.

​Digi ConnectPort LTS 8/16/32 - update to 1.4.9
​Digi ConnectPort TS 8/16 - update to 2.26.2.4
​Digi Connect ES - update to 2.26.2.4

External References

Related Security Bulletins