Deltaww
Deltaww Infrasuite Device Master: vulnerabilidades y CVE
Deltaww Infrasuite Device Master tiene 31 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 13 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE31
Últimos 12 meses0
Críticas13
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-47279 | Alta (7.5) | 1.1% | — | 30 nov 2023 | In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information through a single UDP packet, obtain plaintext credentials, or perform… |
| CVE-2023-47207 | Crítica (9.8) | 17% | — | 30 nov 2023 | In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges. |
| CVE-2023-46690 | Alta (8.8) | 1.9% | — | 30 nov 2023 | In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any file to any location of the filesystem, which could lead to remote code execution. |
| CVE-2023-39226 | Crítica (9.8) | 1.2% | — | 30 nov 2023 | In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute arbitrary code through a single UDP packet. |
| CVE-2023-34316 | Alta (7.5) | 0.61% | — | 10 jul 2023 | An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which could allow an attacker to retrieve file contents. |
| CVE-2023-30765 | Crítica (9.8) | 2.0% | — | 10 jul 2023 | Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege management configurations, resulting in privilege escalation. |
| CVE-2023-34347 | Crítica (9.8) | 0.95% | — | 10 jul 2023 | Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code. |
| CVE-2023-1145 | Alta (7.8) | 0.31% | — | 27 mar 2023 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to… |
| CVE-2023-1144 | Alta (8.8) | 0.65% | — | 27 mar 2023 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an attacker can use the Device-Gateway service and bypass authorization, which could result… |
| CVE-2023-1143 | Alta (8.8) | 0.83% | — | 27 mar 2023 | In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could allow an attacker to remotely execute arbitrary code. |
| CVE-2023-1142 | Crítica (9.8) | 1.1% | — | 27 mar 2023 | In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation. |
| CVE-2023-1141 | Alta (8.8) | 1.6% | — | 27 mar 2023 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could allow an attacker to inject arbitrary commands, which could result in remote code execution. |
| CVE-2023-1140 | Crítica (9.8) | 1.1% | — | 27 mar 2023 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administrator. |
| CVE-2023-1139 | Alta (8.8) | 1.3% | — | 27 mar 2023 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway service, which could allow deserialization of requests prior to… |
| CVE-2023-1138 | Alta (7.5) | 0.57% | — | 27 mar 2023 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could allow an attacker to retrieve Gateway configuration files to obtain plaintext credentials. |
| CVE-2023-1137 | Alta (8.8) | 0.55% | — | 27 mar 2023 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege… |
| CVE-2023-1136 | Alta (7.5) | 0.74% | — | 27 mar 2023 | In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass. |
| CVE-2023-1135 | Alta (7.8) | 0.16% | — | 27 mar 2023 | In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in local privilege escalation. |
| CVE-2023-1134 | Alta (8.8) | 0.66% | — | 27 mar 2023 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to read local files, disclose plaintext credentials, and escalate… |
| CVE-2023-1133 | Crítica (9.8) | 50% | — | 27 mar 2023 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and… |
| CVE-2023-0444 | Alta (8.8) | 0.99% | — | 26 ene 2023 | A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Only User' group, can view the password of another default user… |
| CVE-2022-41778 | Alta (8.8) | 1.0% | — | 13 ene 2023 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide… |
| CVE-2022-41779 | Crítica (9.8) | 1.2% | — | 31 oct 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connects to an attacker-controlled server, the attacker could send… |
| CVE-2022-41776 | Alta (7.5) | 0.58% | — | 31 oct 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which could allow an attacker to provide new values for user configuration… |
| CVE-2022-41772 | Crítica (9.8) | 25% | — | 31 oct 2022 | Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This path traversal could result in remote code execution. |
| CVE-2022-41688 | Alta (7.5) | 0.71% | — | 31 oct 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. An attacker could provide malicious serialized objects that could run… |
| CVE-2022-41657 | Crítica (9.8) | 21% | — | 31 oct 2022 | Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could… |
| CVE-2022-41644 | Alta (8.8) | 0.77% | — | 31 oct 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges. An attacker could use this to create a denial-of-service state or escalate their… |
| CVE-2022-41629 | Crítica (9.1) | 0.67% | — | 31 oct 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could allow an attacker to retrieve any file from the “RunningConfigs”… |
| CVE-2022-40202 | Crítica (9.8) | 1.4% | — | 31 oct 2022 | The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker could provide malicious serialized objects which, when deserialized, could… |