Improper authentication handling for Digi PortServer TS; Digi One SP, SP IA, IA; Digi One IAP
Vulnerability Description
Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022 * Digi One SP/Digi One SP IA/Digi One IA - prior to and including 82000774_Z, build date 10/19/2020 * Digi One IAP – prior to and including 82000770 Z, build date 10/19/2020 A specially crafted POST request to the device’s web interface may allow an unauthenticated attacker to modify configuration settings.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-3659
Credits & Attribution
No credits recorded in the NVD database.
References
- https://hub.digi.com/support/products/infrastructure-management/digi-portserver-ts/
- https://hub.digi.com/support/products/infrastructure-management/digi-one-sp-ia/
- https://hub.digi.com/support/products/infrastructure-management/digi-one-iap-haz/
- https://www.digi.com/getattachment/Resources/Security/Alerts/Improper-authentication-handling-for-Digi-PortServ/improper-authentication-handling.pdf
More from Digi International
View All →Affected Vendor
Digi International
View all reports →