CVE-2023-47279: Delta Electronics InfraSuite Device Master Path Traversal
Published Nov 30, 2023
·Updated
In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information through a single UDP packet, obtain plaintext credentials, or perform NTLM relaying.
Affected Software
2 affected components
: Delta Electronics InfraSuite Device Master<=1.0.7
Deltaww Infrasuite Device Master=1.0.7
Remediation
Information
Delta Electronics recommends updating their software to v1.0.10 https://datacenter-softwarecenter.deltaww.com/Download/UPS/Software/InfraSuite_Device_Master_1.0.10.exe or later.
Event History
Nov 30, 2023
CVE Published
via MITRE·10:12 PM
Data Sourced
via MITRE·10:12 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-47279.
2
What is the severity of CVE-2023-47279?
The severity of CVE-2023-47279 is high, with a severity value of 7.5.
3
What software is affected by CVE-2023-47279?
Delta Electronics InfraSuite Device Master v.1.0.7 is affected by CVE-2023-47279.
4
How can an attacker exploit CVE-2023-47279?
An unauthenticated attacker can exploit CVE-2023-47279 to disclose user information through a single UDP packet, obtain plaintext credentials, or perform NTLM relaying.
5
Is there a fix available for CVE-2023-47279?
There is no information available regarding a fix for CVE-2023-47279. It is recommended to follow the provided reference for updates and guidance.