Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header string when an unauthenticated user is redirected to the authentication page.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://hub.digi.com/support/products/infrastructure-management/digi-passport/ | product patch vendor advisory |
https://github.com/X-C3LL/PoC-CVEs/blob/master/CVE-2022-26952%20%26%20CVE-2022-26953/readme.md | third party advisory exploit |
https://hub.digi.com/dp/path=/support/asset/digi-passport-1.5.2-firmware-release-notes/ | release notes vendor advisory |