Show filters
232 Total Results
Displaying 71-80 of 232
Sort by:
Attacker Value
Unknown
CVE-2023-0444
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Only User' group, can view the password of another default user 'Administrator', which is in the 'Administrator' group. This allows any lower privileged user to log in as an administrator.
0
Attacker Value
Unknown
CVE-2022-4616
Disclosure Date: January 13, 2023 (last updated November 08, 2023)
The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to
command injection through the network diagnosis page. This vulnerability
could allow a remote unauthenticated user to add files, delete files,
and change file permissions.
0
Attacker Value
Unknown
CVE-2022-41778
Disclosure Date: January 13, 2023 (last updated November 08, 2023)
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.
0
Attacker Value
Unknown
CVE-2022-2966
Disclosure Date: December 16, 2022 (last updated February 24, 2025)
Out-of-bounds Read vulnerability in Delta Electronics DOPSoft.This issue affects DOPSoft: All Versions.
0
Attacker Value
Unknown
CVE-2022-42141
Disclosure Date: December 14, 2022 (last updated February 24, 2025)
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.
0
Attacker Value
Unknown
CVE-2022-42140
Disclosure Date: December 14, 2022 (last updated February 24, 2025)
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.
0
Attacker Value
Unknown
CVE-2022-42139
Disclosure Date: December 14, 2022 (last updated February 24, 2025)
Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.
0
Attacker Value
Unknown
CVE-2022-2660
Disclosure Date: December 13, 2022 (last updated February 24, 2025)
Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.
0
Attacker Value
Unknown
CVE-2022-2969
Disclosure Date: December 01, 2022 (last updated February 24, 2025)
Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory.
0
Attacker Value
Unknown
CVE-2022-43452
Disclosure Date: November 17, 2022 (last updated February 24, 2025)
SQL Injection in
FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
0