First published: Mon Oct 31 2022(Updated: )
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connects to an attacker-controlled server, the attacker could send maliciously crafted packets that would be deserialized and executed, leading to remote code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Infrasuite Device Master | <00.00.02a | |
Delta Electronics Version 00.00.01a and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41779 is a vulnerability in Delta Electronics InfraSuite Device Master versions 00.00.01a and prior that allows remote code execution.
CVE-2022-41779 has a severity rating of 9.8 (Critical).
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior are affected by CVE-2022-41779.
CVE-2022-41779 can be exploited by an attacker who sends maliciously crafted packets to the device's server, leading to remote code execution.
There is no specific fix mentioned. It is recommended to upgrade to a version newer than 00.00.02a.