ZDI-23-1753: Delta Electronics InfraSuite Device Master Device-Gateway Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Nov 30, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics InfraSuite Device Master. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2023-47207.
Affected Software
1 affected component
Delta Electronics InfraSuite Device Master
Event History
Nov 30, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1753?
The severity of ZDI-23-1753 is rated at 9.8 on the CVSS scale.
2
What types of attacks can be performed using ZDI-23-1753?
ZDI-23-1753 allows remote attackers to execute arbitrary code on affected installations.
3
Is authentication required to exploit ZDI-23-1753?
No, authentication is not required to exploit the ZDI-23-1753 vulnerability.
4
What software is affected by ZDI-23-1753?
The affected software for ZDI-23-1753 is Delta Electronics InfraSuite Device Master.
5
How can organizations protect themselves from ZDI-23-1753?
Organizations should ensure they apply any security patches or updates provided by Delta Electronics to mitigate ZDI-23-1753.