• Digi International PortServer TS, Digi One SP IA

    From Cisa Advisories@2:263/1 to All on Tue Jul 7 18:33:06 2026
    Digi International PortServer TS, Digi One SP IA

    View CSAF
    Summary
    Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and gain access to restricted resources, obtain credentials, and inject malicious scripts. The following versions of Digi International PortServer TS, Digi One SP IA are affected:

    PortServer TS
    Digi One SP
    Digi One SP IA
    Digi One IA





    CVSS
    Vendor
    Equipment
    Vulnerabilities




    v3 5.9
    Digi International
    Digi International PortServer TS, Digi One SP IA Incorrect Authorization, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')




    Background

    Critical Infrastructure Sectors: Critical Manufacturing, Communications, Information Technology, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States


    Vulnerabilities

    Expand All +

    CVE-2026-12352

    The vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device. View CVE Details

    Affected Products
    Digi International PortServer TS, Digi One SP IA

    Vendor:Digi International
    Product Version:Digi International PortServer TS: <Firmware_2025, Digi International Digi One SP: <Firmware_2025, Digi International Digi One SP IA:
    <Firmware_2025, Digi International Digi One IA: <Firmware_2025
    Product Status:known_affected


    Remediations
    MitigationDigi International recommends users upgrade to Digi Connect EZ or Digi Connect EZ TS as a long term solution. If users are not able to upgrade at this time, the following actions should be taken: Vendor fixFor Digi PortServer TS: Enable HTTPS on the web server. MitigationAlternatively, disable the web server when it is not actively being used for configuration.
    MitigationCompensating control: If you cannot apply the HTTPS configuration, restrict access via firewall or VPN. Vendor fixFor Digi One SP / Digi One SP IA / Digi One IA: Disable the web server. If you cannot apply the HTTPS configuration, restrict access via firewall or VPN.
    MitigationThe following deployment practices are the recommended means of reducing exposure: Deploy the device on a trusted network segment, not exposed to untrusted or public networks.
    MitigationPlace the device behind a firewall or VPN and restrict access to the web management interface to trusted administrative hosts only. MitigationSafeguard administrator credentials, since exploitation requires authenticated administrator access to write the affected fields. MitigationFor assistance users should contact Digi International's support team https://www.digi.com/support.https://www.digi.com/support

    Relevant CWE: CWE-863 Incorrect Authorization

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    5.9
    MEDIUM
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N


    4.0
    8.2
    HIGH
    CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N







    CVE-2026-12948

    A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who views the affected pages. View CVE Details

    Affected Products
    Digi International PortServer TS, Digi One SP IA

    Vendor:Digi International
    Product Version:Digi International PortServer TS: <Firmware_2025, Digi International Digi One SP: <Firmware_2025, Digi International Digi One SP IA:
    <Firmware_2025, Digi International Digi One IA: <Firmware_2025
    Product Status:known_affected


    Remediations
    MitigationDigi International recommends users upgrade to Digi Connect EZ or Digi Connect EZ TS as a long term solution. If users are not able to upgrade at this time, the following actions should be taken: Vendor fixFor Digi PortServer TS: Enable HTTPS on the web server. MitigationAlternatively, disable the web server when it is not actively being used for configuration.
    MitigationCompensating control: If you cannot apply the HTTPS configuration, restrict access via firewall or VPN. Vendor fixFor Digi One SP / Digi One SP IA / Digi One IA: Disable the web server. If you cannot apply the HTTPS configuration, restrict access via firewall or VPN.
    MitigationDigi International recommends users perform the following actions regarding XSS: Digi International will not provide a firmware fix for products affected by CVE-2026-12948, which are approaching end-of-life. Digi International recommends users upgrade to the Digi Connect EZ or Digi Connect EZ TS as a long-term solution.
    MitigationThe following deployment practices are the recommended means of reducing exposure: Deploy the device on a trusted network segment, not exposed to untrusted or public networks.
    MitigationPlace the device behind a firewall or VPN and restrict access to the web management interface to trusted administrative hosts only. MitigationSafeguard administrator credentials, since exploitation requires authenticated administrator access to write the affected fields. MitigationFor assistance users should contact Digi International's support team https://www.digi.com/support.https://www.digi.com/support

    Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    3.8
    LOW
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N


    4.0
    4.8
    MEDIUM
    CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N








    Acknowledgments

    nviCloud reported these vulnerabilities to CISA


    Legal Notice and Terms of Use
    This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).

    Recommended Practices
    CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. CISA reminds organizations to perform proper impact analysis and risk
    assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices
    on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
    CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation
    Strategies.
    Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
    No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.

    Revision History

    Initial Release Date: 2026-07-07




    Date
    Revision
    Summary




    2026-07-07
    1
    Initial Publication




    Legal Notice and Terms of Use

    https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-07

    2026-07-07 12:00 UTC

    --- BBBS/LiR v4.10 Toy-7
    * Origin: LISTS. from TCOB1 READ ONLY (2:263/1)