CVE-2023-1136: Critical severity delta electronics infrasuite device master vulnerability
Published Mar 27, 2023
·Updated
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass.
Affected Software
2 affected components
Deltaww Infrasuite Device Master<1.0.5
Delta Electronics Versions prior to 1.0.5
Event History
Mar 27, 2023
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2023-1136.
2
What is the severity of CVE-2023-1136?
The severity of CVE-2023-1136 is critical, with a CVSS score of 7.5.
3
What is the affected software for CVE-2023-1136?
The affected software for CVE-2023-1136 is Delta Electronics InfraSuite Device Master versions prior to 1.0.5.
4
What is the impact of CVE-2023-1136?
CVE-2023-1136 allows an unauthenticated attacker to generate a valid token, leading to authentication bypass.
5
Is there a fix available for CVE-2023-1136?
Yes, a fix is available for CVE-2023-1136. Update to version 1.0.5 or later of Delta Electronics InfraSuite Device Master.