Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-36767

EPSS 0.36% · P58
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-36767

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The server will reply with a weakly-hashed version of the server's access password. The attacker may then crack this hash offline in order to successfully login to the server.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Digi RealPort 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Digi RealPort是一种专有的 Serial-over-LAN 封装协议。它通过将 ICS 协议数据封装在基于 TCP 的协议中,为网络上任何地方的串行设备提供虚拟连接。 Digi RealPort存在安全漏洞,攻击者可利用该漏洞向服务器发送未经身份验证的请求,服务器将用服务器访问密码的弱散列版本进行应答,攻击者可利用该漏洞可能会脱机破解进而成功登录到服务器。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2021-36767

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-36767

登录查看更多情报信息。

Same Patch Batch · n/a · 2021-10-08 · 17 CVEs total

CVE-2021-418022.9 LOWHashicorp HashiCorp Vault 安全漏洞
CVE-2021-42112LimeSurvey 跨站脚本漏洞
CVE-2020-22617Ardour 资源管理错误漏洞
CVE-2021-42109VITEC Exterity IPTV 安全漏洞
CVE-2021-32029PostgreSQL 缓冲区错误漏洞
CVE-2021-20600Mitsubishi Electric MELSEC iQ-R series 资源管理错误漏洞
CVE-2021-41920webTareas SQL注入漏洞
CVE-2021-41919webTareas 代码问题漏洞
CVE-2021-41918webTareas 跨站脚本漏洞
CVE-2021-41917webTareas 跨站脚本漏洞
CVE-2021-41916webTareas 跨站请求伪造漏洞
CVE-2021-41825Verint Systems Verint Workforce Optimization 跨站脚本漏洞
CVE-2021-3312Alkacon OpenCms 代码问题漏洞
CVE-2021-35979Digi RealPort 访问控制错误漏洞
CVE-2021-35977Digi RealPort 安全漏洞
CVE-2021-41947Subrion CMS SQL注入漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2021-36767

No comments yet


Leave a comment