CVE-2023-47207: Delta Electronics InfraSuite Device Master Deserialization of Untrusted Data
Published Nov 30, 2023
·Updated
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges.
Affected Software
2 affected components
Deltaww Infrasuite Device Master=1.0.7
: Delta Electronics InfraSuite Device Master<=1.0.7
Remediation
Information
Delta Electronics recommends updating their software to v1.0.10 https://datacenter-softwarecenter.deltaww.com/Download/UPS/Software/InfraSuite_Device_Master_1.0.10.exe or later.
Event History
Nov 30, 2023
CVE Published
10:09 PM
Data Sourced
10:09 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-47207.
2
What is the severity of CVE-2023-47207?
The severity of CVE-2023-47207 is critical with a score of 9.8 (out of 10).
3
What is the affected software?
The affected software is Delta Electronics InfraSuite Device Master version 1.0.7.
4
How can an attacker exploit CVE-2023-47207?
An unauthenticated attacker can exploit CVE-2023-47207 to execute code with local administrator privileges.
5
Is there a fix available for CVE-2023-47207?
Please refer to the official reference link for information on available fixes for CVE-2023-47207.