8.8
CVSSv3

CVE-2021-37188

Published: 10/12/2021 Updated: 12/07/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

An issue exists on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firmware (because the bootloader does not verify that it is authentic), changing the behavior of the gateway.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

digi transport_dr64_firmware

digi transport_dr64_firmware -

digi transport_vc74_firmware

digi transport_wr11_firmware

digi transport_wr11_xt_firmware

digi transport_wr21_firmware

digi transport_wr31_firmware

digi transport_wr41_firmware

digi transport_wr44_firmware