CVE-2020-6973: XSS
Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228K 08/09/2018), bios Version 1.2. Multiple cross-site scripting vulnerabilities exist that could allow an attacker to cause a denial-of-service condition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Digi International ConnectPort LTS 32 MEIto a version that resolves this vulnerability.Fixed in 1.4.3 (82002228_K 08/09/2018)Patch Multiple cross-site scripting vulnerabilities - Compensating control
Mitigate the potential cross-site scripting impact by restricting access to the ConnectPort web interface to trusted clients (e.g., via network ACL/firewall) to reduce exposure.
Event History
Frequently Asked Questions
What is CVE-2020-6973?
CVE-2020-6973 refers to multiple cross-site scripting vulnerabilities in Digi International ConnectPort LTS 32 MEI firmware version 1.4.3 and bios version 1.2.
What is the severity of CVE-2020-6973?
The severity of CVE-2020-6973 is medium with a severity value of 6.2.
How can an attacker exploit CVE-2020-6973?
An attacker can exploit CVE-2020-6973 by causing a denial-of-service condition on the affected system.
Which versions of Digi ConnectPort LTS 32 MEI Firmware are affected by CVE-2020-6973?
Digi ConnectPort LTS 32 MEI Firmware version 1.4.3 is affected by CVE-2020-6973.
Is Digi ConnectPort LTS 32 MEI vulnerable to CVE-2020-6973?
No, Digi ConnectPort LTS 32 MEI is not vulnerable to CVE-2020-6973.
How can I fix CVE-2020-6973?
Apply the necessary patches or updates provided by Digi International to fix CVE-2020-6973.