A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who views the affected pages (CWE-79).
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Digi International | Digi One IA | >= 82000774_Z, <= 82000774_ABCNA affecteddefault unaffected | |
| Digi International | Digi One SP IA | >= 82000774_Z, <= 82000774_ABCNA affecteddefault unaffected | |
| Digi International | Digi One SP | >= 82000774_Z, <= 82000774_ABCNA affecteddefault unaffected | |
| Digi International | Digi PortServer TS | >= 82000747_V1, <= 82000747_ABCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.