Showing 2 vulnerabilities on this page for Digi One IA

Signals CISA KEV Ransomware Nuclei
Digi International vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Stored Cross-Site Scripting (XSS)

A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who views the affected pages (CWE-79).

CWE-79Jul 7, 2026
CVSS4.8v4.0EPSS0.269%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Digi RealPort Protocol Use of Password Hash Instead of Password for Authentication

Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment.

CWE-836Aug 31, 2023
CVSS9.0v3.1EPSS0.55%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX