Description
This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.
Published: 2026-07-07
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows unauthenticated actors to bypass the device’s authentication mechanism and gain access to restricted resources. It is an authorization bypass, classified as CWE‑863, and can enable reading or modifying device configuration data without legitimate credentials.

Affected Systems

The affected products are Digi One SP, Digi One SP IA, Digi One IA, and PortServer TS series (1, 2, and 4). Specific firmware versions are not identified in the advisory, so all devices in these families are potentially vulnerable until a patch is deployed.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote access to the device’s management interface; the attacker requires only network connectivity to the device and no prior credentials.

Generated by OpenCVE AI on July 28, 2026 at 09:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Digi International that resolves the authorization flaw.
  • Restrict management access by disabling unused ports or placing the device behind a firewall, VLAN, or other network segmentation to limit reachability.
  • If a patch is not yet available, block external traffic to the device’s management interface and enforce strict network segmentation to reduce exposure.

Generated by OpenCVE AI on July 28, 2026 at 09:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Digi International
Digi International digi One Sp / Sp Ia / Ia
Digi International portserver Ts 1/2/4
Vendors & Products Digi International
Digi International digi One Sp / Sp Ia / Ia
Digi International portserver Ts 1/2/4

Tue, 07 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.
Title Incorrect Authorization
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Digi International Digi One Sp / Sp Ia / Ia Portserver Ts 1/2/4
cve-icon MITRE

Status: PUBLISHED

Assigner: Digi

Published:

Updated: 2026-07-13T16:21:10.700Z

Reserved: 2026-06-15T21:08:54.168Z

Link: CVE-2026-12352

cve-icon Vulnrichment

Updated: 2026-07-07T14:56:44.774Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:30:19Z

Weaknesses