Database/Control plane, storage & DevOps

Digi RealPort protocol (Digi console/terminal servers): RealPort is the protocol Digi console servers use to expose
Impact
RealPort is the protocol Digi console servers use to expose their serial ports as virtual COM ports over the network. Its authentication can be replayed — an attacker who captures a legitimate auth exchange (e.g. via a network tap or ARP spoof on the management VLAN) can replay it to open a session on connected serial equipment without knowing the real password.
Who can reach it
Requires network visibility into a RealPort authentication exchange (passive capture is enough) and the ability to send the replayed traffic to the target console server — no credential cracking needed.
What to do
Firmware/software upgrade on the RealPort driver and the console server firmware to a version with replay-resistant authentication; also a network-segmentation fix — RealPort traffic should never traverse a network segment an untrusted party can sniff. Rollout is a firmware flash per device plus a driver update on every host connecting to RealPort ports.
References
Related entries
- Ivanti Connect Secure: Stack-based buffer overflowCVE-2025-0282 · Ivanti Connect SecureCritical
- Ivanti Connect Secure/ZTA: Stack-based buffer overflowCVE-2025-22457 · Ivanti Connect Secure/ZTACritical
- GitLab: unsanitized HTML in the CI job modal lets a developer-role user escalate privilegesCVE-2026-16627 · GitLab CE/EE (CI job modal HTML rendering)Critical
- Woodpecker CI: pipeline authors can pick any ServiceAccount for their build podsCVE-2026-61549 · Woodpecker CI Kubernetes backend (backend_options.kubernetes.serviceAccountName)Critical
- Jenkins Remoting: JEP-200 deserialization filter bypassed via fallback class resolution on the controllerCVE-2026-70426 · Jenkins Remoting (JEP-200 deserialization class filter, fallback resolution path)Critical
- Crossplane package manager (cosign signature verification via ImageConfig): SUPPLY CHAIN, TIME-OF-CHECK TO TIME-OF-USENCVD-2026-055-crossplane-package-manager-cosig · Crossplane package manager (cosign signature verification via ImageConfig)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.