First published: Mon Oct 31 2022(Updated: )
The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker could provide malicious serialized objects which, when deserialized, could activate an opcode for a backup scheduling function without authentication. This function allows the user to designate all function arguments and the file to be executed. This could allow the attacker to start any new process and achieve remote code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Infrasuite Device Master | <00.00.02a | |
Delta Electronics Version 00.00.01a and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40202 is a vulnerability in the database backup function in Delta Electronics InfraSuite Device Master versions 00.00.01a and prior.
CVE-2022-40202 allows attackers to activate an opcode for a backup scheduling function without authentication.
CVE-2022-40202 has a severity rating of 9.8 (Critical).
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior are affected by CVE-2022-40202.
No fix is currently available for CVE-2022-40202. It is recommended to follow the guidance provided by Delta Electronics or apply any security patches or updates when they become available.