First published: Mon Oct 31 2022(Updated: )
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This path traversal could result in remote code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Infrasuite Device Master | <00.00.02a | |
Delta Electronics Version 00.00.01a and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41772 is a vulnerability in Delta Electronics InfraSuite Device Master versions 00.00.01a and prior that mishandles .ZIP archives containing characters used in path traversal, which could result in remote code execution.
The severity of CVE-2022-41772 is critical with a CVSS score of 9.8.
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior are affected by CVE-2022-41772.
The path traversal vulnerability in CVE-2022-41772 can be exploited by manipulating .ZIP archives containing specific characters.
It is recommended to update Delta Electronics InfraSuite Device Master to version 00.00.02a or later to fix the vulnerability in CVE-2022-41772.