Show filters
232 Total Results
Displaying 71-80 of 232
Sort by:
Attacker Value
Unknown

CVE-2023-0444

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Only User' group, can view the password of another default user 'Administrator', which is in the 'Administrator' group. This allows any lower privileged user to log in as an administrator.
Attacker Value
Unknown

CVE-2022-4616

Disclosure Date: January 13, 2023 (last updated November 08, 2023)
The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis page. This vulnerability could allow a remote unauthenticated user to add files, delete files, and change file permissions.
Attacker Value
Unknown

CVE-2022-41778

Disclosure Date: January 13, 2023 (last updated November 08, 2023)
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.
Attacker Value
Unknown

CVE-2022-2966

Disclosure Date: December 16, 2022 (last updated February 24, 2025)
Out-of-bounds Read vulnerability in Delta Electronics DOPSoft.This issue affects DOPSoft: All Versions.
Attacker Value
Unknown

CVE-2022-42141

Disclosure Date: December 14, 2022 (last updated February 24, 2025)
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.
Attacker Value
Unknown

CVE-2022-42140

Disclosure Date: December 14, 2022 (last updated February 24, 2025)
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.
Attacker Value
Unknown

CVE-2022-42139

Disclosure Date: December 14, 2022 (last updated February 24, 2025)
Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.
Attacker Value
Unknown

CVE-2022-2660

Disclosure Date: December 13, 2022 (last updated February 24, 2025)
Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.
Attacker Value
Unknown

CVE-2022-2969

Disclosure Date: December 01, 2022 (last updated February 24, 2025)
Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory.
Attacker Value
Unknown

CVE-2022-43452

Disclosure Date: November 17, 2022 (last updated February 24, 2025)
SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network