ZDI-23-906: Delta Electronics InfraSuite Device Master Device-Gateway Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Jul 10, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics InfraSuite Device Master. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Delta Electronics InfraSuite Device Master
Event History
Jul 10, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-906?
ZDI-23-906 is classified as a critical severity vulnerability.
2
How do I fix ZDI-23-906?
To fix ZDI-23-906, ensure you update the Delta Electronics InfraSuite Device Master to the latest version provided by the vendor.
3
What types of attacks can ZDI-23-906 facilitate?
ZDI-23-906 allows attackers to remotely execute arbitrary code on vulnerable installations.
4
Is authentication required to exploit ZDI-23-906?
No, authentication is not required to exploit ZDI-23-906.
5
Which product is affected by ZDI-23-906?
ZDI-23-906 affects the Delta Electronics InfraSuite Device Master.