CVE-2022-41776

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which could allow an attacker to provide new values for user configuration files such as UserListInfo.xml. This could lead to the changing of administrative passwords.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-07 Patch Third Party Advisory US Government Resource
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:deltaww:infrasuite_device_master:*:*:*:*:*:*:*:*

Information

Published : 2022-10-31 13:15

Updated : 2022-11-02 07:04


NVD link : CVE-2022-41776

Mitre link : CVE-2022-41776


JSON object : View

CWE
CWE-306

Missing Authentication for Critical Function

Advertisement

dedicated server usa

Products Affected

deltaww

  • infrasuite_device_master