Unauthenticated Authentication Bypass (CVE‑2026‑12352) in Digi International PortServer TS & Digi One SP IA Devices
What It Is — A CISA advisory reports CVE‑2026‑12352, a vulnerability in Digi International’s PortServer TS and Digi One SP IA hardware that lets an unauthenticated actor bypass authentication, harvest credentials, and inject malicious scripts.
Exploitability — The flaw is remotely exploitable without credentials; a proof‑of‑concept exists in the advisory. CVSS v3 base score 5.9 (Moderate).
Affected Products — Digi International PortServer TS, Digi One SP, Digi One SP IA, Digi One IA (firmware < 2025).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access Control criteria (CC6.1 Logical Access) require documented, enforceable authentication mechanisms; a bypass directly violates that control.
- Continuous monitoring of vendor‑supplied OT assets must capture firmware version and authentication logs to provide audit evidence of control effectiveness.
- Enterprise buyers increasingly demand proof that third‑party devices are patched and that access‑control failures are tracked in a SOC 2‑ready evidence repository.
Recommended Actions
- Inventory all Digi PortServer and Digi One devices; verify firmware version.
- Apply Digi International’s firmware ≥ 2025 patch immediately; document the patch as evidence of remediation.
- Enable and forward authentication logs to your SIEM; map the logs to SOC 2 CC6.1 for continuous evidence.
- Update your vendor‑risk register to reflect the new vulnerability and remediation status.
- Conduct a post‑remediation audit of access‑control policies and test for residual authentication weaknesses.
Source: CISA Advisory – ICSA‑26‑188‑07