Vulnerabilities > Deltaww > Infrasuite Device Master > High

DATE CVE VULNERABILITY TITLE RISK
2023-03-27 CVE-2023-1143 Unspecified vulnerability in Deltaww Infrasuite Device Master 00.00.01A/00.00.02A
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could allow an attacker to remotely execute arbitrary code.
network
low complexity
deltaww
8.8
2023-03-27 CVE-2023-1144 Incorrect Authorization vulnerability in Deltaww Infrasuite Device Master 00.00.01A/00.00.02A
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an attacker can use the Device-Gateway service and bypass authorization, which could result in privilege escalation.
network
low complexity
deltaww CWE-863
8.8
2023-03-27 CVE-2023-1145 Deserialization of Untrusted Data vulnerability in Deltaww Infrasuite Device Master 00.00.01A/00.00.02A
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.
local
low complexity
deltaww CWE-502
7.8
2023-01-26 CVE-2023-0444 Unspecified vulnerability in Deltaww Infrasuite Device Master 00.00.02A
A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a.
network
low complexity
deltaww
8.8
2023-01-13 CVE-2022-41778 Unspecified vulnerability in Deltaww Infrasuite Device Master 00.00.01A
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification.
network
low complexity
deltaww
8.8
2022-10-31 CVE-2022-41644 Missing Authentication for Critical Function vulnerability in Deltaww Infrasuite Device Master 00.00.01A
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges.
network
low complexity
deltaww CWE-306
8.8
2022-10-31 CVE-2022-41688 Unspecified vulnerability in Deltaww Infrasuite Device Master 00.00.01A
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups.
network
low complexity
deltaww
7.5
2022-10-31 CVE-2022-41776 Unspecified vulnerability in Deltaww Infrasuite Device Master 00.00.01A
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which could allow an attacker to provide new values for user configuration files such as UserListInfo.xml.
network
low complexity
deltaww
7.5