First published: Thu Jan 12 2023(Updated: )
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Infrasuite Device Master | <=00.00.01a | |
Delta Electronics Version 00.00.01a and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Delta Electronics InfraSuite Device Master is CVE-2022-41778.
The severity level of CVE-2022-41778 is critical.
The affected software for CVE-2022-41778 is Delta Electronics InfraSuite Device Master versions 00.00.01a and prior.
CVE-2022-41778 allows an attacker to execute arbitrary code upon deserialization by providing malicious serialized objects.
There is currently no fix available for CVE-2022-41778. It is recommended to follow the guidance provided by the vendor and apply any necessary patches or updates when they become available.