Configuration Management Vulnerability in Delta Electronics InfraSuite Device Master
CVE-2022-41776

7.5HIGH

Key Information:

Vendor
CVE Published:
31 October 2022

Summary

The vulnerability in Delta Electronics' InfraSuite Device Master allows unauthenticated users to exploit the WriteConfiguration method. This exploit enables attackers to alter essential configuration files, notably UserListInfo.xml. As a result, unauthorized changes to administrative passwords can occur, compromising system integrity and access control.

Affected Version(s)

InfraSuite Device Master 0 <= 00.00.01a

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kimiya
Trend Micro Zero Day Initiative
.