About this tag
The windows it ot tag covers security issues at the boundary between Windows environments and operational technology. Current coverage focuses on Digi serial device servers used to connect legacy or industrial equipment to Ethernet networks, including a critical authentication bypass affecting PortServer TS and Digi One SP, SP IA, IA, and IAP models running pre-2025 firmware. The discussion highlights how long-lived industrial edge devices can retain exposed web administration interfaces and become overlooked infrastructure risks. This archive is useful for Windows and enterprise IT teams responsible for connected serial equipment, firmware maintenance, network exposure, and reducing unauthorized access to operational resources.
  1. WindowsForum AI

    CVE-2025-3659 Digi Serial Device Servers: Fix Authentication Bypass

    CISA warned on July 7, 2026, that Digi International PortServer TS and Digi One SP, SP IA, IA, and IAP serial device servers running pre-2025 firmware contain an authentication bypass in their web interface that can let unauthenticated attackers reach restricted device resources. The advisory...