First published: Mon Mar 27 2023(Updated: )
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to read local files, disclose plaintext credentials, and escalate privileges.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Infrasuite Device Master | <1.0.5 | |
Delta Electronics Versions prior to 1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1134 is a path traversal vulnerability in Delta Electronics InfraSuite Device Master versions prior to 1.0.5.
CVE-2023-1134 allows an attacker to read local files, disclose plaintext credentials, and escalate privileges in Delta Electronics InfraSuite Device Master versions prior to 1.0.5.
CVE-2023-1134 has a severity rating of 8.8 (high).
An attacker can exploit CVE-2023-1134 by using a path traversal technique to access files outside the intended directory in Delta Electronics InfraSuite Device Master versions prior to 1.0.5.
Yes, updating Delta Electronics InfraSuite Device Master to version 1.0.5 or newer will fix the vulnerability.