Impact
The vulnerability allows unauthenticated actors to bypass the device’s authentication mechanism and gain access to restricted resources. It is an authorization bypass, classified as CWE‑863, and can enable reading or modifying device configuration data without legitimate credentials.
Affected Systems
The affected products are Digi One SP, Digi One SP IA, Digi One IA, and PortServer TS series (1, 2, and 4). Specific firmware versions are not identified in the advisory, so all devices in these families are potentially vulnerable until a patch is deployed.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote access to the device’s management interface; the attacker requires only network connectivity to the device and no prior credentials.
OpenCVE Enrichment