CVE-2023-34347: Delta Electronics InfraSuite Device Master Deserialization of Untrusted Data
?Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code.
Other sources
Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta Electronics InfraSuite Device Masterto a version that resolves this vulnerability.Fixed in 1.0.7
Event History
Frequently Asked Questions
What is CVE-2023-34347?
CVE-2023-34347 is a vulnerability in Delta Electronics InfraSuite Device Master versions prior to 1.0.7 that allows an attacker to remotely execute arbitrary code.
How severe is CVE-2023-34347?
CVE-2023-34347 has a severity rating of critical with a score of 9 out of 10.
What does the vulnerability affect?
The vulnerability affects Delta Electronics InfraSuite Device Master versions prior to 1.0.7.
How can an attacker exploit CVE-2023-34347?
An attacker can exploit CVE-2023-34347 by sending malicious input to the affected software, leading to remote code execution.
Is there a fix for CVE-2023-34347?
Yes, updating to version 1.0.7 or later of Delta Electronics InfraSuite Device Master resolves the vulnerability.