Home/Product/deltaww infrasuite device master
Product

deltaww infrasuite device master

31 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-47279
all versions
In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose
7.5HIGH
CVE-2023-47207
all versions
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute c
9.8CRITICAL
CVE-2023-46690
all versions
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any file to any
8.8HIGH
CVE-2023-39226
all versions
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute a
9.8CRITICAL
CVE-2023-34316
< 1.0.7
​An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which could all
6.5MEDIUM
CVE-2023-30765
< 1.0.7
​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacke
8.8HIGH
CVE-2023-34347
< 1.0.7
​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could al
9.8CRITICAL
CVE-2023-1145
< 1.0.5
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the D
7.8HIGH
CVE-2023-1144
< 1.0.5
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an a
8.8HIGH
CVE-2023-1143
< 1.0.5
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could allow an att
8.8HIGH
CVE-2023-1142
< 1.0.5
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files
7.5HIGH
CVE-2023-1141
< 1.0.5
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could allow an a
8.8HIGH
CVE-2023-1140
< 1.0.5
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve
9.8CRITICAL
CVE-2023-1139
< 1.0.5
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the D
8.8HIGH
CVE-2023-1138
< 1.0.5
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could a
7.5HIGH
CVE-2023-1137
< 1.0.5
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract
6.5MEDIUM
CVE-2023-1136
< 1.0.5
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, w
9.8CRITICAL
CVE-2023-1135
< 1.0.5
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, whic
7.8HIGH
CVE-2023-1134
< 1.0.5
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could all
7.1HIGH
CVE-2023-1133
< 1.0.5
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service list
9.8CRITICAL
CVE-2023-0444
all versions
A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which
8.8HIGH
CVE-2022-41778
<= 00.00.01a
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device
9.8CRITICAL
CVE-2022-41779
< 00.00.02a
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. I
8.8HIGH
CVE-2022-41776
< 00.00.02a
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfigurat
7.5HIGH
CVE-2022-41772
< 00.00.02a
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path
9.8CRITICAL
CVE-2022-41688
< 00.00.02a
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and m
9.8CRITICAL
CVE-2022-41657
< 00.00.02a
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memor
9.8CRITICAL
CVE-2022-41644
< 00.00.02a
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group pri
8.8HIGH
CVE-2022-41629
< 00.00.02a
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoi
7.5HIGH
CVE-2022-40202
< 00.00.02a
The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authenticatio
9.8CRITICAL
CVE-2022-38142
< 00.00.02a
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device
9.8CRITICAL
threatengine.sh