CVE-2022-26952: Buffer Overflow
Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header string when an unauthenticated user is redirected to the authentication page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-26952?
CVE-2022-26952 is a vulnerability found in the Digi Passport Firmware through version 1.5.1.1.
How severe is CVE-2022-26952?
CVE-2022-26952 has a severity rating of 7.5 (High).
What is the affected software by CVE-2022-26952?
The affected software by CVE-2022-26952 is Digi Passport Firmware through version 1.5.1.1.
How does CVE-2022-26952 impact unauthenticated users?
CVE-2022-26952 can lead to a buffer overflow when an unauthenticated user is redirected to the authentication page.
Are there any references for CVE-2022-26952?
Yes, you can find more information about CVE-2022-26952 in the following references: [Reference 1](https://github.com/X-C3LL/PoC-CVEs/blob/master/CVE-2022-26952%20%26%20CVE-2022-26953/readme.md), [Reference 2](https://hub.digi.com/dp/path=/support/asset/digi-passport-1.5.2-firmware-release-notes/), [Reference 3](https://hub.digi.com/support/products/infrastructure-management/digi-passport/).