First published: Mon Mar 27 2023(Updated: )
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Infrasuite Device Master | <1.0.5 | |
Delta Electronics Versions prior to 1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-1137.
The severity of CVE-2023-1137 is high with a score of 8.8.
The affected software for CVE-2023-1137 is Delta Electronics InfraSuite Device Master versions prior to 1.0.5.
CVE-2023-1137 allows a low-level user to extract files and plaintext credentials of administrator users, resulting in privilege escalation.
Yes, the fix for CVE-2023-1137 is to update Delta Electronics InfraSuite Device Master to version 1.0.5 or newer.