CVE-2021-36767 - CVE House
Back to Database
Status published Critical CVE-2021-36767

In Digi RealPort through 4.10.490, authentication relies on a challenge-response...

Vulnerability Description

In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The server will reply with a weakly-hashed version of the server's access password. The attacker may then crack this hash offline in order to successfully login to the server.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-36767

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

realport, connectport ts 8\/16 firmware, connectport lts 8\/16\/32 firmware, passport integrated console server firmware, cm firmware, portserver ts firmware, portserver ts mei firmware, portserver ts mei hardened firmware, portserver ts m mei firmware, 6350-sr firmware, portserver ts p mei firmware, transport wr11 xt firmware, one ia firmware, wr31 firmware, wr44 r firmware, connect es firmware, wr21 firmware, one iap firmware, one iap haz firmware
Vulnerable Versions:
0

Timeline

Official Publish: October 8th, 2021
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.