8.8

CVE-2024-50627

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file upload feature. It allows an attacker on the local area network (with specific permissions) to upload and execute malicious files, potentially leading to unauthorized system access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Digi ≫ Connectport Lts Firmware Version < 1.4.12
   Digi ≫ Connectport Lts 16 Version -
   Digi ≫ Connectport Lts 16 Mei Version -
   Digi ≫ Connectport Lts 16 Mei 2ac Version -
   Digi ≫ Connectport Lts 32 Version -
   Digi ≫ Connectport Lts 32 Mei Version -
   Digi ≫ Connectport Lts 8 Mei Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.24
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

https://www.digi.com/resources/security
Vendor Advisory
https://www.digi.com/getattachment/Resources/Security/Alerts/Digi-ConnectPort-LTS-Firmware-Update/ConnectPort-LTS-KB.pdf
Vendor Advisory
https://www.digi.com/resources/documentation/digidocs/pdfs/90001001.pdf
Product