CVE-2023-1137: High severity delta electronics infrasuite device master vulnerability
Published Mar 27, 2023
·Updated
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation.
Affected Software
2 affected components
Deltaww Infrasuite Device Master<1.0.5
Delta Electronics Versions prior to 1.0.5
Event History
Mar 27, 2023
CVE Published
via MITRE·02:44 PM
Data Sourced
via MITRE·02:44 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-1137.
2
What is the severity of CVE-2023-1137?
The severity of CVE-2023-1137 is high with a score of 8.8.
3
What is the affected software for CVE-2023-1137?
The affected software for CVE-2023-1137 is Delta Electronics InfraSuite Device Master versions prior to 1.0.5.
4
What is the risk of CVE-2023-1137?
CVE-2023-1137 allows a low-level user to extract files and plaintext credentials of administrator users, resulting in privilege escalation.
5
Is there a fix available for CVE-2023-1137?
Yes, the fix for CVE-2023-1137 is to update Delta Electronics InfraSuite Device Master to version 1.0.5 or newer.