Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
deltaww infrasuite device master vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2023-0444
A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Only User' group, can view the password of another default user 'Administrator', which is in the 'A...
Deltaww Infrasuite Device Master 00.00.02a
8.8
CVSSv3
CVE-2022-41778
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserial...
Deltaww Infrasuite Device Master
8.8
CVSSv3
CVE-2022-41644
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges. An attacker could use this to create a denial-of-service state or escalate their own privileges.
Deltaww Infrasuite Device Master
7.8
CVSSv3
CVE-2023-1135
In Delta Electronics InfraSuite Device Master versions before 1.0.5, an attacker could set incorrect directory permissions, which could result in local privilege escalation.
Deltaww Infrasuite Device Master
7.8
CVSSv3
CVE-2023-1145
Delta Electronics InfraSuite Device Master versions before 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.
Deltaww Infrasuite Device Master
7.5
CVSSv3
CVE-2023-47279
In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated malicious user to disclose user information through a single UDP packet, obtain plaintext credentials, or perform NTLM relaying.
Deltaww Infrasuite Device Master 1.0.7
7.5
CVSSv3
CVE-2023-34316
?An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions before 1.0.7) patch, which could allow an malicious user to retrieve file contents.
Deltaww Infrasuite Device Master
7.5
CVSSv3
CVE-2023-1136
In Delta Electronics InfraSuite Device Master versions before 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass.
Deltaww Infrasuite Device Master
7.5
CVSSv3
CVE-2023-1138
Delta Electronics InfraSuite Device Master versions before 1.0.5 contain an improper access control vulnerability, which could allow an malicious user to retrieve Gateway configuration files to obtain plaintext credentials.
Deltaww Infrasuite Device Master
7.5
CVSSv3
CVE-2022-41776
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which could allow an malicious user to provide new values for user configuration files such as UserListInfo.xml. This could lead to the c...
Deltaww Infrasuite Device Master
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »