Vulnerabilities > Deltaww > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-10-03 CVE-2024-43699 SQL Injection vulnerability in Deltaww Diaenergie
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx.
network
low complexity
deltaww CWE-89
critical
9.8
2024-08-29 CVE-2024-8255 Deserialization of Untrusted Data vulnerability in Deltaww DTN Soft
Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrusted data vulnerability.
network
low complexity
deltaww CWE-502
critical
9.8
2023-11-30 CVE-2023-39226 Unspecified vulnerability in Deltaww Infrasuite Device Master 1.0.7
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute arbitrary code through a single UDP packet.
network
low complexity
deltaww
critical
9.8
2023-11-30 CVE-2023-47207 Deserialization of Untrusted Data vulnerability in Deltaww Infrasuite Device Master 1.0.7
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges.
network
low complexity
deltaww CWE-502
critical
9.8
2023-07-10 CVE-2023-30765 Unspecified vulnerability in Deltaww Infrasuite Device Master 00.00.01A/00.00.02A/1.0.5
?Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege management configurations, resulting in privilege escalation.
network
low complexity
deltaww
critical
9.8
2023-07-10 CVE-2023-34347 Unspecified vulnerability in Deltaww Infrasuite Device Master 00.00.01A/00.00.02A/1.0.5
?Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code.
network
low complexity
deltaww
critical
9.8
2023-03-31 CVE-2023-0432 Cross-site Scripting vulnerability in Deltaww Dx-2100L1-Cn Firmware
The web configuration service of the affected device contains an authenticated command injection vulnerability.
network
low complexity
deltaww CWE-79
critical
9.0
2023-03-27 CVE-2023-1133 Deserialization of Untrusted Data vulnerability in Deltaww Infrasuite Device Master 00.00.01A/00.00.02A
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default.
network
low complexity
deltaww CWE-502
critical
9.8
2023-03-27 CVE-2023-1140 Missing Authentication for Critical Function vulnerability in Deltaww Infrasuite Device Master 00.00.01A/00.00.02A
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administrator.
network
low complexity
deltaww CWE-306
critical
9.8
2023-03-27 CVE-2023-1142 Path Traversal vulnerability in Deltaww Infrasuite Device Master 00.00.01A/00.00.02A
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation.
network
low complexity
deltaww CWE-22
critical
9.8