CVE-2022-41778: Critical severity delta electronics infrasuite device master vulnerability
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Delta Electronics InfraSuite Device Master?
The vulnerability ID for Delta Electronics InfraSuite Device Master is CVE-2022-41778.
What is the severity level of CVE-2022-41778?
The severity level of CVE-2022-41778 is critical.
What is the affected software for CVE-2022-41778?
The affected software for CVE-2022-41778 is Delta Electronics InfraSuite Device Master versions 00.00.01a and prior.
How does CVE-2022-41778 work?
CVE-2022-41778 allows an attacker to execute arbitrary code upon deserialization by providing malicious serialized objects.
Is there a fix for CVE-2022-41778?
There is currently no fix available for CVE-2022-41778. It is recommended to follow the guidance provided by the vendor and apply any necessary patches or updates when they become available.