Impact
A stored cross‑site scripting flaw exists in the web management interface of several Digi International devices, allowing a remote, authenticated administrator to inject malicious JavaScript into select configuration fields. Once stored, the payload is executed each time a user visits the affected pages, running in that user’s browser context. This can lead to theft or manipulation of data displayed or processed in the browser, compromising confidentiality and integrity for end users that view the insecure pages.
Affected Systems
The vulnerability applies to Digi One IA, Digi One SP, Digi One SP IA, and Digi PortServer TS devices. No firmware or hardware version restriction is documented, so any installed firmware that provides the exposed web interface and contains the vulnerable configuration fields is at risk. Administrators should verify that their firmware version includes the applicable fix or a patch that mitigates the issue.
Risk and Exploitability
The CVSS score of 4.8 reflects a medium severity, and the EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation. The flaw requires the attacker to be an authenticated administrator; however, once a malicious script is stored, it can impact any user who later views the affected page. The vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known active exploits at this time. The attack path is limited to users with management interface access, but the stored nature of the script enables broader impact across all users of the system.
OpenCVE Enrichment