CVE-2021-38412 - CVE House
Back to Database
Status published Critical CVE-2021-38412

Digi PortServer TS 16 Improper Authentication

Vulnerability Description

Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication tokens. This vulnerability could allow an attacker to enable the SNMP service and manipulate the community strings to achieve further control in.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-38412

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Digi International

View all reports →

Affected Software

PortServer TS 16
Vulnerable Versions:
Firmware

Timeline

Official Publish: September 17th, 2021
Last Modified: September 17th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Weaknesses (CWE)