Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-50628


An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12. It allows an attacker on the local area network to achieve unauthorized manipulation of resources, which may lead to remote code execution when combined with other issues.


Published

2024-12-09T22:15:22.977

Last Modified

2025-06-27T16:06:32.573

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System digi connectport_lts_firmware < 1.4.12 Yes
Hardware digi connectport_lts_16 - No
Hardware digi connectport_lts_16_mei - No
Hardware digi connectport_lts_16_mei_2ac - No
Hardware digi connectport_lts_32 - No
Hardware digi connectport_lts_32_mei - No
Hardware digi connectport_lts_8_mei - No

References