First published: Mon Oct 31 2022(Updated: )
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Delta Electronics Version 00.00.01a and prior | ||
Delta Electronics InfraSuite Device Master | <00.00.02a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38142 is a vulnerability in Delta Electronics InfraSuite Device Master versions 00.00.01a and prior that allows an attacker to execute arbitrary code through the deserialization of malicious serialized objects.
The severity of CVE-2022-38142 is critical with a CVSS score of 9.8.
CVE-2022-38142 affects Delta Electronics InfraSuite Device Master versions 00.00.01a and prior by allowing the deserialization of user-supplied data without proper verification, which can lead to arbitrary code execution.
To fix CVE-2022-38142, it is recommended to update Delta Electronics InfraSuite Device Master to version 00.00.02a or later.
You can find more information about CVE-2022-38142 on the official US-CERT/ICS-CERT website: https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-07