First published: Mon Jul 10 2023(Updated: )
?Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Infrasuite Device Master | <1.0.7 | |
Delta Electronics InfraSuite Device Master | <1.0.7 | 1.0.7 |
Delta Electronics has provided a fix to these vulnerabilities. Users are encouraged to update to the latest version. * Delta Electronics InfraSuite Device Master: Update to v1.0.7 https://datacenter-softwarecenter.deltaww.com/Download/UPS/Software/InfraSuite_Device_Master_1.0.7(x64).exe .
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34347 is a vulnerability in Delta Electronics InfraSuite Device Master versions prior to 1.0.7 that allows an attacker to remotely execute arbitrary code.
CVE-2023-34347 has a severity rating of critical with a score of 9 out of 10.
The vulnerability affects Delta Electronics InfraSuite Device Master versions prior to 1.0.7.
An attacker can exploit CVE-2023-34347 by sending malicious input to the affected software, leading to remote code execution.
Yes, updating to version 1.0.7 or later of Delta Electronics InfraSuite Device Master resolves the vulnerability.