CVE-2023-1138: High severity delta electronics infrasuite device master vulnerability
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could allow an attacker to retrieve Gateway configuration files to obtain plaintext credentials.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-1138?
CVE-2023-1138 is an improper access control vulnerability in Delta Electronics InfraSuite Device Master versions prior to 1.0.5.
What is the severity of CVE-2023-1138?
CVE-2023-1138 has a severity rating of 7.5, which is considered high.
How does CVE-2023-1138 affect Delta Electronics InfraSuite Device Master?
CVE-2023-1138 allows an attacker to retrieve Gateway configuration files to obtain plaintext credentials.
Is there a fix available for CVE-2023-1138?
Yes, updating to version 1.0.5 of Delta Electronics InfraSuite Device Master resolves the vulnerability.
Where can I find more information about CVE-2023-1138?
You can find more information about CVE-2023-1138 in the advisory published by CISA at the following link: https://www.cisa.gov/news-events/ics-advisories/icsa-23-080-02