CVE-2021-36767 Details
Description
In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The server will reply with a weakly-hashed version of the server's access password. The attacker may then crack this hash offline in order to successfully login to the server.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://raw.githubusercontent.com/reidmefirst/vuln-disclosure/main/2021-02.txt | CVE | Third Party Advisory |
| https://raw.githubusercontent.com/reidmefirst/vuln-disclosure/main/2021-02.txt | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-916 | Use of Password Hash With Insufficient Computational Effort | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| digi realport | <= 1.9-40 <= 4.10.490 |
CPE
Remediation
| |
| digi connectport ts 8/16 firmware | All versions |
CPE
Remediation
| |
| digi connectport ts 8/16 | All versions |
CPE
Remediation
| |
| digi connectport lts 8/16/32 firmware | All versions |
CPE
Remediation
| |
| digi connectport lts 8/16/32 | All versions |
CPE
Remediation
| |
| digi passport integrated console server firmware | All versions |
CPE
Remediation
| |
| digi passport integrated console server | All versions |
CPE
Remediation
| |
| digi cm firmware | All versions |
CPE
Remediation
| |
| digi cm | All versions |
CPE
Remediation
| |
| digi portserver ts firmware | All versions |
CPE
Remediation
| |
| digi portserver ts | All versions |
CPE
Remediation
| |
| digi portserver ts mei firmware | All versions |
CPE
Remediation
| |
| digi portserver ts mei | All versions |
CPE
Remediation
| |
| digi portserver ts mei hardened firmware | All versions |
CPE
Remediation
| |
| digi portserver ts mei hardened | All versions |
CPE
Remediation
| |
| digi portserver ts m mei firmware | All versions |
CPE
Remediation
| |
| digi portserver ts m mei | All versions |
CPE
Remediation
| |
| digi 6350-sr firmware | All versions |
CPE
Remediation
| |
| digi 6350-sr | All versions |
CPE
Remediation
| |
| digi portserver ts p mei firmware | All versions |
CPE
Remediation
| |
| digi portserver ts p mei | All versions |
CPE
Remediation
| |
| digi transport wr11 xt firmware | All versions |
CPE
Remediation
| |
| digi transport wr11 xt | All versions |
CPE
Remediation
| |
| digi one ia firmware | All versions |
CPE
Remediation
| |
| digi one ia | All versions |
CPE
Remediation
| |
| digi wr31 firmware | All versions |
CPE
Remediation
| |
| digi wr31 | All versions |
CPE
Remediation
| |
| digi wr44 r firmware | All versions |
CPE
Remediation
| |
| digi wr44 r | All versions |
CPE
Remediation
| |
| digi connect es firmware | All versions |
CPE
Remediation
| |
| digi connect es | All versions |
CPE
Remediation
| |
| digi wr21 firmware | All versions |
CPE
Remediation
| |
| digi wr21 | All versions |
CPE
Remediation
| |
| digi one iap firmware | All versions |
CPE
Remediation
| |
| digi one iap | All versions |
CPE
Remediation
| |
| digi one iap haz firmware | All versions |
CPE
Remediation
| |
| digi one iap haz | All versions |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Sep 25, 2023 | Reanalysis | [email protected] |
| May 26, 2023 | Reanalysis | [email protected] |
| Apr 29, 2022 | Modified Analysis | [email protected] |
| Jan 1, 2022 | CVE Modified | [email protected] |
| Oct 19, 2021 | Initial Analysis | [email protected] |