Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment.
Solution:
Workaround:
The product records password hashes in a data store, receives a hash of a password from a client, and compares the supplied hash to the hash obtained from the data store.
Link | Tags |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-243-04 | third party advisory us government resource |
https://www.digi.com/getattachment/resources/security/alerts/realport-cves/Dragos-Disclosure-Statement.pdf | vendor advisory |