CVE-2021-35978
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges. This allows an attacker (with knowledge of the protocol) to execute arbitrary code on the controller including overwriting firmware, adding/removing users, disabling the internal firewall, etc.
Affected (11)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.2.4.9 |
| Running on/with | Platform Versions |
|---|---|
Digi Transport Dr64 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Digi Transport Sr44 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.2.4.9 |
| Running on/with | Platform Versions |
|---|---|
Digi Transport Vc74 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 8.2.1.3 |
| Running on/with | Platform Versions |
|---|---|
Digi Transport Wr11 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 8.2.1.3 |
| Running on/with | Platform Versions |
|---|---|
Digi Transport Wr11 Xt | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 8.2.1.3 |
| Running on/with | Platform Versions |
|---|---|
Digi Transport Wr21 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 8.2.1.3 |
| Running on/with | Platform Versions |
|---|---|
Digi Transport Wr31 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.0.0.0 to 5.2.4.6 |
| Running on/with | Platform Versions |
|---|---|
Digi Transport Wr41 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 8.3.1.2 |
| Running on/with | Platform Versions |
|---|---|
Digi Transport Wr44 | Version v2 |
References (4)
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.