VYPR

PortServer TS

by Digi International Inc

CVEs (3)

  • CVE-2021-38412CriSep 17, 2021
    risk 0.63cvss 9.6epss 0.01

    Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication tokens. This vulnerability could allow an attacker to enable the SNMP service and manipulate the…

  • CVE-2025-3659CriMay 12, 2025
    risk 0.61cvss —epss 0.00

    Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022 * Digi One SP/Digi One SP IA/Digi One IA - prior to and including…

  • CVE-2026-12948MedJul 7, 2026
    risk 0.31cvss —epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script…