First published: Mon Oct 31 2022(Updated: )
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. An attacker could provide malicious serialized objects that could run these functions without authentication to create a new user and add them to the administrator group.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Infrasuite Device Master | <00.00.02a | |
Delta Electronics Version 00.00.01a and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-41688.
The severity of CVE-2022-41688 is critical.
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior are affected.
CVE-2022-41688 allows an attacker to create and modify user groups without authentication.
A fix for CVE-2022-41688 is not available at the moment. It is recommended to follow the guidance provided by the vendor or the responsible authority.