Show filters
32 Total Results
Displaying 1-10 of 32
Sort by:
Attacker Value
High

CVE-2023-1133

Disclosure Date: March 27, 2023 (last updated October 08, 2023)
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.
Attacker Value
Unknown

CVE-2024-10456

Disclosure Date: October 30, 2024 (last updated October 31, 2024)
Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication.
0
Attacker Value
Unknown

CVE-2023-47279

Disclosure Date: November 30, 2023 (last updated December 07, 2023)
In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information through a single UDP packet, obtain plaintext credentials, or perform NTLM relaying.
Attacker Value
Unknown

CVE-2023-47207

Disclosure Date: November 30, 2023 (last updated December 07, 2023)
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges.
Attacker Value
Unknown

CVE-2023-46690

Disclosure Date: November 30, 2023 (last updated December 07, 2023)
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any file to any location of the filesystem, which could lead to remote code execution.
Attacker Value
Unknown

CVE-2023-39226

Disclosure Date: November 30, 2023 (last updated December 07, 2023)
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute arbitrary code through a single UDP packet.
Attacker Value
Unknown

CVE-2023-34316

Disclosure Date: July 10, 2023 (last updated November 08, 2023)
​An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which could allow an attacker to retrieve file contents.
Attacker Value
Unknown

CVE-2023-30765

Disclosure Date: July 10, 2023 (last updated January 27, 2025)
​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege management configurations, resulting in privilege escalation.
Attacker Value
Unknown

CVE-2023-34347

Disclosure Date: July 10, 2023 (last updated November 08, 2023)
​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code.
Attacker Value
Unknown

CVE-2023-1145

Disclosure Date: March 27, 2023 (last updated November 08, 2023)
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.