Configuration Management Vulnerability in Delta Electronics InfraSuite Device Master
CVE-2022-41776
7.5HIGH
Summary
The vulnerability in Delta Electronics' InfraSuite Device Master allows unauthenticated users to exploit the WriteConfiguration method. This exploit enables attackers to alter essential configuration files, notably UserListInfo.xml. As a result, unauthorized changes to administrative passwords can occur, compromising system integrity and access control.
Affected Version(s)
InfraSuite Device Master 0 <= 00.00.01a
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
kimiya
Trend Micro Zero Day Initiative