Skip to main content

Vendor archive

digi CVEs

Beta · best-effort

24 CVEs tagged to vendor digi7 Critical, 11 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2022-26953

Published Apr 6, 2022

Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow. An attacker can supply a string in the page parameter for reboot.asp endpoint, allowing him to force an ov…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26952

Published Apr 6, 2022

Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header string when an unauthenticated user is redirected to the a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37189

Published Dec 10, 2021

An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the use…

CVSS 7.5 · High

CVE-2017-18868

Published May 21, 2020

Digi XBee 2 devices do not have an effective protection mechanism against remote AT commands, because of issues related to the network stack upon which the ZigBee protocol is buil…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1973

Published Apr 27, 2004

DiGi Web Server allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request that contains a large number of / (slash) characters, which consumes…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1