VendorsDeltawwinfrasuite_device_masterany version
Vulnerabilities

Deltaww Delta Electronics any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

26CVEs
CVE-2023-1133
CVE-2023-1133
Published 2023-03-27 · Modified
9.8EPSS 0.501
CVE-2022-41772
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This path traversal could result in remote code execution.
Published 2022-10-31 · Modified
9.8EPSS 0.249
CVE-2022-41657
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could create arbitrary files, which could be used in API operations and could ultimately result in remote code execution.
Published 2022-10-31 · Modified
9.8EPSS 0.209
CVE-2022-38142
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.
Published 2022-10-31 · Modified
9.8EPSS 0.182
CVE-2023-30765
​Delta Electronics InfraSuite Device Master Improper Access Control
Published 2023-07-10 · Modified
9.8EPSS 0.020
CVE-2022-40202
The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker could provide malicious serialized objects which, when deserialized, could activate an opcode for a backup scheduling function without authentication. This function allows the user to designate all function arguments and the file to be executed. This could allow the attacker to start any new process and achieve remote code execution.
Published 2022-10-31 · Modified
9.8EPSS 0.013
CVE-2022-41779
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connects to an attacker-controlled server, the attacker could send maliciously crafted packets that would be deserialized and executed, leading to remote code execution.
Published 2022-10-31 · Modified
9.8EPSS 0.011
CVE-2023-1142
CVE-2023-1142
Published 2023-03-27 · Modified
9.8EPSS 0.011
CVE-2023-1140
CVE-2023-1140
Published 2023-03-27 · Modified
9.8EPSS 0.011
CVE-2022-41778
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.
Published 2023-01-12 · Modified
9.8EPSS 0.010
CVE-2023-34347
​Delta Electronics InfraSuite Device Master Deserialization of Untrusted Data
Published 2023-07-10 · Modified
9.8EPSS 0.010
CVE-2023-1136
CVE-2023-1136
Published 2023-03-27 · Modified
9.8EPSS 0.007
CVE-2022-41688
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. An attacker could provide malicious serialized objects that could run these functions without authentication to create a new user and add them to the administrator group.
Published 2022-10-31 · Modified
9.8EPSS 0.007
CVE-2022-41629
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could allow an attacker to retrieve any file from the “RunningConfigs” directory. The attacker could then view and modify configuration files such as UserListInfo.xml, which would allow them to see existing administrative passwords.
Published 2022-10-31 · Modified
9.1EPSS 0.006
CVE-2023-1141
CVE-2023-1141
Published 2023-03-27 · Modified
8.8EPSS 0.016
CVE-2023-1139
CVE-2023-1139
Published 2023-03-27 · Modified
8.8EPSS 0.013
CVE-2023-1143
CVE-2023-1143
Published 2023-03-27 · Modified
8.8EPSS 0.008
CVE-2022-41644
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges. An attacker could use this to create a denial-of-service state or escalate their own privileges.
Published 2022-10-31 · Modified
8.8EPSS 0.007
CVE-2023-1134
CVE-2023-1134
Published 2023-03-27 · Modified
8.8EPSS 0.007
CVE-2023-1144
CVE-2023-1144
Published 2023-03-27 · Modified
8.8EPSS 0.006
CVE-2023-1137
CVE-2023-1137
Published 2023-03-27 · Modified
8.8EPSS 0.006
CVE-2023-1145
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.
Published 2023-03-27 · Modified
7.8EPSS 0.003
CVE-2023-1135
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in local privilege escalation.
Published 2023-03-27 · Modified
7.8EPSS 0.002
CVE-2023-34316
Delta Electronics InfraSuite Device Master Improper Access Control
Published 2023-07-10 · Modified
7.5EPSS 0.006
CVE-2023-1138
CVE-2023-1138
Published 2023-03-27 · Modified
7.5EPSS 0.006
CVE-2022-41776
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which could allow an attacker to provide new values for user configuration files such as UserListInfo.xml. This could lead to the changing of administrative passwords.
Published 2022-10-31 · Modified
7.5EPSS 0.005