Vulnerability Details CVE-2021-37188
An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firmware (because the bootloader does not verify that it is authentic), changing the behavior of the gateway.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 48.8%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2021-37188
-
cpe:2.3:h:digi:transport_dr64:-
-
cpe:2.3:h:digi:transport_sr44:-
-
cpe:2.3:h:digi:transport_vc74:-
-
cpe:2.3:h:digi:transport_wr11:-
-
cpe:2.3:h:digi:transport_wr11_xt:-
-
cpe:2.3:h:digi:transport_wr21:-
-
cpe:2.3:h:digi:transport_wr31:-
-
cpe:2.3:h:digi:transport_wr41:-
-
cpe:2.3:h:digi:transport_wr44:v2
-
cpe:2.3:o:digi:transport_dr64_firmware:-
-
cpe:2.3:o:digi:transport_dr64_firmware:5.2.4.9
-
cpe:2.3:o:digi:transport_vc74_firmware:-
-
cpe:2.3:o:digi:transport_vc74_firmware:5.2.4.9
-
cpe:2.3:o:digi:transport_wr11_firmware:-
-
cpe:2.3:o:digi:transport_wr11_firmware:6.0.0.0
-
cpe:2.3:o:digi:transport_wr11_firmware:8.2.1.3
-
cpe:2.3:o:digi:transport_wr11_xt_firmware:-
-
cpe:2.3:o:digi:transport_wr11_xt_firmware:6.0.0.0
-
cpe:2.3:o:digi:transport_wr11_xt_firmware:8.2.1.3
-
cpe:2.3:o:digi:transport_wr21_firmware:-
-
cpe:2.3:o:digi:transport_wr21_firmware:5.2.2.3
-
cpe:2.3:o:digi:transport_wr21_firmware:6.0.0.0
-
cpe:2.3:o:digi:transport_wr21_firmware:8.2.1.3
-
cpe:2.3:o:digi:transport_wr31_firmware:*
-
cpe:2.3:o:digi:transport_wr41_firmware:5.0.0.0
-
cpe:2.3:o:digi:transport_wr41_firmware:5.2.4.6
-
cpe:2.3:o:digi:transport_wr41_firmware:6.0.0.0
-
cpe:2.3:o:digi:transport_wr41_firmware:6.1.3.5
-
cpe:2.3:o:digi:transport_wr41_firmware:8.0.0.0
-
cpe:2.3:o:digi:transport_wr41_firmware:8.0.0.3
-
cpe:2.3:o:digi:transport_wr41_firmware:8.1.0.1
-
cpe:2.3:o:digi:transport_wr41_firmware:8.2.0.2
-
cpe:2.3:o:digi:transport_wr41_firmware:8.3.0.1
-
cpe:2.3:o:digi:transport_wr41_firmware:8.3.1.2
-
cpe:2.3:o:digi:transport_wr44_firmware:-
-
cpe:2.3:o:digi:transport_wr44_firmware:5.1.6.4
-
cpe:2.3:o:digi:transport_wr44_firmware:5.1.6.9
-
cpe:2.3:o:digi:transport_wr44_firmware:6.0.0.0
-
cpe:2.3:o:digi:transport_wr44_firmware:8.3.1.2