Deserialization Vulnerability in Delta Electronics InfraSuite Device Master
CVE-2022-41778
9.8CRITICAL
What is CVE-2022-41778?
The Delta Electronics InfraSuite Device Master versions 00.00.01a and earlier contain a significant deserialization vulnerability. This flaw allows an attacker to send specially crafted user-supplied data via the Device-DataCollect service. Without adequate checks, the system may deserialize these malicious objects, potentially resulting in arbitrary code execution. Organizations using these affected versions should review their security measures and apply necessary updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
InfraSuite Device Master 0 <= 00.00.01a