Vulnerabilities > CVE-2023-1136 - Incorrect Authorization vulnerability in Deltaww Infrasuite Device Master 00.00.01A/00.00.02A

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
deltaww
CWE-863

Summary

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass.

Common Weakness Enumeration (CWE)