CVE-2022-38142: Critical severity delta electronics infrasuite device master vulnerability
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-38142?
CVE-2022-38142 is a vulnerability in Delta Electronics InfraSuite Device Master versions 00.00.01a and prior that allows an attacker to execute arbitrary code through the deserialization of malicious serialized objects.
What is the severity of CVE-2022-38142?
The severity of CVE-2022-38142 is critical with a CVSS score of 9.8.
How does CVE-2022-38142 affect Delta Electronics InfraSuite Device Master?
CVE-2022-38142 affects Delta Electronics InfraSuite Device Master versions 00.00.01a and prior by allowing the deserialization of user-supplied data without proper verification, which can lead to arbitrary code execution.
How can I fix CVE-2022-38142?
To fix CVE-2022-38142, it is recommended to update Delta Electronics InfraSuite Device Master to version 00.00.02a or later.
Where can I find more information about CVE-2022-38142?
You can find more information about CVE-2022-38142 on the official US-CERT/ICS-CERT website: https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-07