CVE-2021-35979
Published Oct 8, 2021An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication.
Vendor/product archive
2 CVEs tagged to digi / one_iap_family_firmware — 1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication.
An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP discovery response messages. This could result in arbitrar…