Incorrect Access Control Vulnerability in Digisol Router
Published May 10, 2024
6.8
MEDIUMCVSS 4.0
EPSS 0.56%
Description
This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by identifying UART pins and accessing the root shell on the vulnerable system.
Successful exploitation of this vulnerability could allow the attacker to access the sensitive information on the targeted system.
Affected products
-
- Version v3.2.02StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Digisol | Digisol Router DG-GR1321 | unaffected |
|
No data.
-
- Version 3.2.02StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Digisol | DG-Gr1321 Firmware | unaffected |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade Digisol Router firmware to version v3.1.02-240311. https://www.digisol.com/firmware/
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-32783 Advisory
- https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0158 third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-32783 | Advisory | |
| https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0158 | third-party-advisory |
Change history (0)
No recorded changes yet.