Vulnerabilities (CVE)

Filtered by CWE-836
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-48925 2025-07-01 N/A 4.3 MEDIUM
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.
CVE-2023-4299 1 Digi 39 Cm, Cm Firmware, Connect Es and 36 more 2024-11-21 N/A 9.0 CRITICAL
Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment.