NA

CVE-2022-41688

Published: 31/10/2022 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. An attacker could provide malicious serialized objects that could run these functions without authentication to create a new user and add them to the administrator group.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

deltaww infrasuite device master

ICS Advisories

Delta Electronics InfraSuite Device Master
Critical Infrastructure Sectors: Energy