First published: Fri Mar 31 2023(Updated: )
The web configuration service of the affected device contains an authenticated command injection vulnerability. It can be used to execute system commands on the operating system (OS) from the device in the context of the user "root." If the attacker has credentials for the web service, then the device could be fully compromised.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Dx-2100l1-cn Firmware | <1.5.0.12 | |
Deltaww Dx-2100l1-cn | ||
Delta Electronics DX-2100-L1-CN | =1.5.0.10 |
Delta Electronics patched this vulnerability in Version 1.5.0.12 https://downloadcenter.deltaww.com/en-US/DownloadCenter and recommends all users update device firmware to that version or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0432 is a web configuration service vulnerability that allows authenticated command injection with root user privileges.
CVE-2023-0432 has a severity level of critical with a value of 9.
The Deltaww Dx-2100l1-cn Firmware up to version 1.5.0.12 is affected by CVE-2023-0432.
CVE-2023-0432 can be exploited by an attacker with web service credentials to execute system commands on the affected device.
No, the Deltaww Dx-2100l1-cn device is not vulnerable to CVE-2023-0432.