CVE-2023-4299

HIGH EPSS 41.9%
Published Aug 31, 20232y ago · Modified Jun 17, 20261w ago
8.1 CVSS 3.1
High
Find Similar
Published Aug 31, 2023 2y ago
Last Modified Jun 17, 2026 1w ago

Description

Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment.

CVSS Details

Base Score
8.1
Exploitability
2.2
Impact
5.9
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
41.9% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-836

Affected Products 40

VendorProductVersionRange
digirealport* ≤1.9-40
digirealport* ≤4.8.488.0
digiconnectport_ts_8\/16_firmware* <2.26.2.4
digiconnectport_ts_8\/16*any
digipassport_firmware*any
digipassport*any
digiconnectport_lts_8\/16\/32_firmware* <1.4.9
digiconnectport_lts_8\/16\/32*any
digicm_firmware*any
digicm*any
digiportserver_ts_firmware*any
digiportserver_ts*any
digiportserver_ts_mei_firmware*any
digiportserver_ts_mei*any
digiportserver_ts_mei_hardened_firmware*any
digiportserver_ts_mei_hardened*any
digiportserver_ts_m_mei_firmware*any
digiportserver_ts_m_mei*any
digiportserver_ts_p_mei_firmware*any
digiportserver_ts_p_mei*any
digione_iap_firmware*any
digione_iap*any
digione_ia_firmware*any
digione_ia*any
digione_sp_ia_firmware*any
digione_sp_ia*any
digione_sp_firmware*any
digione_sp*any
digiwr31_firmware*any
digiwr31*any
digitransport_wr11_xt_firmware*any
digitransport_wr11_xt*any
digiwr44_r_firmware*any
digiwr44_r*any
digiwr21_firmware*any
digiwr21*any
digiconnect_es_firmware* <2.26.2.4
digiconnect_es*any
digiconnect_sp_firmware*any
digiconnect_sp*any

References 2

  • cisa.gov https://www.cisa.gov/news-events/ics-advisories/icsa-23-243-04
    Third Party AdvisoryUS Government Resource
  • digi.com https://www.digi.com/getattachment/resources/security/alerts/realport-cves/Dragos-Disclosure-Statement.pdf
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.