CVE-2020-8822: XSS
Published Feb 10, 2020
·Updated
Digi TransPort WR21 5.2.2.3, WR44 5.1.6.4, and WR44v2 5.1.6.9 devices allow stored XSS in the web application.
Affected Software
12 affected components
Digi Transport Wr21 Firmware=5.2.2.3
Digi TransPort WR21
Digi Transport Wr44 Firmware=5.1.6.4
Digi Transport Wr44
Digi Transport Wr44 Firmware=5.1.6.9
Digi Transport Wr44=2
All of the following
Digi Transport Wr21 Firmware=5.2.2.3
Digi TransPort WR21
All of the following
Digi Transport Wr44 Firmware=5.1.6.4
Digi Transport Wr44
All of the following
Digi Transport Wr44 Firmware=5.1.6.9
Digi Transport Wr44=2
Event History
Feb 10, 2020
CVE Published
via MITRE·01:52 AM
Data Sourced
via MITRE·01:52 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-8822?
CVE-2020-8822 is a vulnerability in Digi TransPort WR21 5.2.2.3, WR44 5.1.6.4, and WR44v2 5.1.6.9 devices that allows stored XSS in the web application.
2
What is the severity of CVE-2020-8822?
The severity of CVE-2020-8822 is medium with a severity value of 4.8.
3
How does CVE-2020-8822 affect Digi TransPort WR21 devices?
CVE-2020-8822 affects Digi TransPort WR21 devices with firmware version 5.2.2.3.
4
How does CVE-2020-8822 affect Digi TransPort WR44 devices?
CVE-2020-8822 affects Digi TransPort WR44 devices with firmware versions 5.1.6.4 and 5.1.6.9.
5
How can I mitigate the risk of the CVE-2020-8822 vulnerability?
To mitigate the risk of the CVE-2020-8822 vulnerability, it is recommended to update the firmware of the affected Digi TransPort devices to a non-vulnerable version.