ZDI-23-1755: Delta Electronics InfraSuite Device Master RunScript Exposed Dangerous Method Remote Code Execution Vulnerability
Published Nov 30, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics InfraSuite Device Master. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2023-39226.
Affected Software
1 affected component
Delta Electronics InfraSuite Device Master
Event History
Nov 30, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1755?
The severity of ZDI-23-1755 is rated at 9.8 on the CVSS scale.
2
What type of attack does ZDI-23-1755 enable?
ZDI-23-1755 allows remote attackers to execute arbitrary code on affected installations.
3
Is authentication required to exploit ZDI-23-1755?
No, authentication is not required to exploit the ZDI-23-1755 vulnerability.
4
Which software is affected by ZDI-23-1755?
ZDI-23-1755 affects Delta Electronics InfraSuite Device Master installations.
5
How can I mitigate the risks associated with ZDI-23-1755?
Mitigation for ZDI-23-1755 typically involves applying available software updates or security patches.