Home › Intelligence › Brief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Unauthenticated Authentication Bypass (CVE‑2026‑12352) in Digi International PortServer TS & Digi One SP IA Devices

CISA has disclosed CVE‑2026‑12352, a remote authentication‑bypass flaw in Digi International’s PortServer TS and Digi One SP IA hardware. The vulnerability threatens SOC 2 access‑control compliance because it undermines logical access safeguards and requires immediate firmware remediation.

LiveThreat™ Intelligence · 📅 July 07, 2026· 📰 cisa.gov
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
5 recommended
📰
Source
cisa.gov

Unauthenticated Authentication Bypass (CVE‑2026‑12352) in Digi International PortServer TS & Digi One SP IA Devices

What It Is — A CISA advisory reports CVE‑2026‑12352, a vulnerability in Digi International’s PortServer TS and Digi One SP IA hardware that lets an unauthenticated actor bypass authentication, harvest credentials, and inject malicious scripts.

Exploitability — The flaw is remotely exploitable without credentials; a proof‑of‑concept exists in the advisory. CVSS v3 base score 5.9 (Moderate).

Affected Products — Digi International PortServer TS, Digi One SP, Digi One SP IA, Digi One IA (firmware < 2025).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Control criteria (CC6.1 Logical Access) require documented, enforceable authentication mechanisms; a bypass directly violates that control.
  • Continuous monitoring of vendor‑supplied OT assets must capture firmware version and authentication logs to provide audit evidence of control effectiveness.
  • Enterprise buyers increasingly demand proof that third‑party devices are patched and that access‑control failures are tracked in a SOC 2‑ready evidence repository.

Recommended Actions

  • Inventory all Digi PortServer and Digi One devices; verify firmware version.
  • Apply Digi International’s firmware ≥ 2025 patch immediately; document the patch as evidence of remediation.
  • Enable and forward authentication logs to your SIEM; map the logs to SOC 2 CC6.1 for continuous evidence.
  • Update your vendor‑risk register to reflect the new vulnerability and remediation status.
  • Conduct a post‑remediation audit of access‑control policies and test for residual authentication weaknesses.

Source: CISA Advisory – ICSA‑26‑188‑07

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-07 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →