CVE-2023-0444: High severity delta electronics infrasuite device master vulnerability
A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Only User' group, can view the password of another default user 'Administrator', which is in the 'Administrator' group. This allows any lower privileged user to log in as an administrator.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this privilege escalation vulnerability?
The vulnerability ID for this privilege escalation vulnerability is CVE-2023-0444.
What software is affected by this vulnerability?
The Delta Electronics InfraSuite Device Master version 00.00.02a is affected by this vulnerability.
What is the severity rating of CVE-2023-0444?
CVE-2023-0444 has a severity rating of 8.8, which is considered high.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by using a default user 'User' in the 'Read Only User' group to view the password of the 'Administrator' user, allowing them to escalate their privileges.
Is there a fix available for this vulnerability?
It is recommended to update to a patched version of Delta Electronics InfraSuite Device Master to mitigate this vulnerability.