First published: Mon Mar 27 2023(Updated: )
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could allow an attacker to retrieve Gateway configuration files to obtain plaintext credentials.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Infrasuite Device Master | <1.0.5 | |
Delta Electronics Versions prior to 1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1138 is an improper access control vulnerability in Delta Electronics InfraSuite Device Master versions prior to 1.0.5.
CVE-2023-1138 has a severity rating of 7.5, which is considered high.
CVE-2023-1138 allows an attacker to retrieve Gateway configuration files to obtain plaintext credentials.
Yes, updating to version 1.0.5 of Delta Electronics InfraSuite Device Master resolves the vulnerability.
You can find more information about CVE-2023-1138 in the advisory published by CISA at the following link: https://www.cisa.gov/news-events/ics-advisories/icsa-23-080-02