← Knowledge Center
Advisory CVE-2026-12352

Digi PortServer TS and Digi One SP IA Flaws Allow Auth Bypass, Credential Theft

CISA has published an ICS advisory covering vulnerabilities in Digi International’s PortServer TS and Digi One SP IA serial device servers. The key issue (CVE-2026-12352) is an incorrect authorization flaw that lets an unauthenticated attacker bypass authentication and reach restricted resources on the device. A separate cross-site scripting weakness allows injection of malicious scripts, and the advisory notes that exploitation could enable an attacker to obtain credentials.

For identity teams, the authentication-bypass and credential-exposure angle is the concern: these devices sit in critical manufacturing, communications, IT, and transportation environments, and captured credentials could be reused to pivot deeper into networks or feed lateral movement toward identity infrastructure.

What to take away: inventory affected Digi devices, apply the 2025 firmware updates, and treat any credentials stored or transmitted through these device servers as potentially exposed—rotate them and restrict management interface access.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.