Database/Control plane, storage & DevOps

Digi ConnectPort LTS (before 1.4.12): An attacker who can reach the ConnectPort LTS's file-upload feature
Impact
An attacker who can reach the ConnectPort LTS's file-upload feature with only limited/local-network privileges can upload and execute a malicious file, escalating straight to full control of the device — which puts them on the cellular/serial gateway path some fleets use for out-of-band access when the primary network is down.
Who can reach it
Requires local-area-network reach to the device's web upload feature and some baseline permission level (not full admin); no internet-facing exposure needed if the device is on a segmented OOB VLAN, but that's exactly the network this appliance is meant to be reachable from.
What to do
Software upgrade to ConnectPort LTS firmware 1.4.12 or later. This is a firmware flash per unit; because ConnectPort LTS is frequently the fallback OOB path when the primary network is unavailable, schedule the upgrade during planned maintenance rather than waiting for an outage to force it.
References
Related entries
- Deep Sea Electronics DSE855 generator communications gateway: Six unauthenticated flaws in one device: two stack-basedCVE-2024-5948 · Deep Sea Electronics DSE855 generator communications gatewayHigh
- PostgreSQL: TOCTOU race in pg_dumpCVE-2024-7348 · PostgreSQLHigh
- Automated Logic / Carrier i-Vu Gen5 BACnet router (drv_gen5_106-01-2380) and i-Vu Zone Controller: Malformed BACnetCVE-2025-0657 · Automated Logic / Carrier i-Vu Gen5 BACnet router (drv_gen5_106-01-2380) and i-Vu Zone ControllerHigh
- Veeam Backup & Replication: Remote code execution reachable by any domain user on a domain-joined backup serverCVE-2025-23120 · Veeam Backup & ReplicationHigh
- Veeam Backup & Replication: Authenticated domain user achieves remote code execution on the Backup ServerCVE-2025-23121 · Veeam Backup & ReplicationHigh
- Dell OpenManage Network Integration (RADIUS auth bypass): An attacker on the local network forges a valid RADIUS AcceptCVE-2025-36593 · Dell OpenManage Network Integration (RADIUS auth bypass)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.