CVEs (31)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Only User' group, can view the password of another default user 'Administr...Show more |
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide maliciou...Show more |
1Deltaww 1Infrasuite Device Master Nov 21, 2024 Oct 31, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connects to an attacker-controlled server, the attacker could send malicious...Show more |
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which could allow an attacker to provide new values for user configuration fi...Show more |
1Deltaww 1Infrasuite Device Master Nov 21, 2024 Oct 31, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This path traversal could result in remote code execution.
|
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. An attacker could provide malicious serialized objects that could run...Show more |
1Deltaww 1Infrasuite Device Master Nov 21, 2024 Oct 31, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could cre...Show more |
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges. An attacker could use this to create a denial-of-service state or escalate the...Show more |
1Deltaww 1Infrasuite Device Master Nov 21, 2024 Oct 31, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could allow an attacker to retrieve any file from the “RunningConfigs” director...Show more |
1Deltaww 1Infrasuite Device Master Nov 21, 2024 Oct 31, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker could provide malicious serialized objects which, when deserialized, could...Show more |
1Deltaww 1Infrasuite Device Master Nov 21, 2024 Oct 31, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious se...Show more |