ZDI-23-1752: Delta Electronics InfraSuite Device Master UploadMedia Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics InfraSuite Device Master. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-46690.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1752?
The severity of ZDI-23-1752 is rated at 8.8 on the CVSS scale.
How do I fix ZDI-23-1752?
To fix ZDI-23-1752, ensure that you apply the latest security patches provided by Delta Electronics for InfraSuite Device Master.
Who can exploit ZDI-23-1752?
ZDI-23-1752 can be exploited by remote attackers who have valid authentication to the affected system.
What type of vulnerability is ZDI-23-1752?
ZDI-23-1752 is a remote code execution vulnerability that allows attackers to execute arbitrary code.
What products are affected by ZDI-23-1752?
The vulnerability ZDI-23-1752 affects installations of Delta Electronics InfraSuite Device Master.