Описание
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connects to an attacker-controlled server, the attacker could send maliciously crafted packets that would be deserialized and executed, leading to remote code execution.
Ссылки
- PatchThird Party AdvisoryUS Government Resource
- PatchThird Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 00.00.02a (исключая)
cpe:2.3:a:deltaww:infrasuite_device_master:*:*:*:*:*:*:*:*
EPSS
Процентиль: 65%
0.00486
Низкий
8.8 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-502
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connects to an attacker-controlled server, the attacker could send maliciously crafted packets that would be deserialized and executed, leading to remote code execution.
EPSS
Процентиль: 65%
0.00486
Низкий
8.8 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-502