ZDI-CAN-19279: ZDI-23-677: Delta Electronics InfraSuite Device Master CtrlLayerNWCmd_ReportFileOperation Directory Traversal Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Delta Electronics InfraSuite Device Master. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19279?
The severity of ZDI-CAN-19279 is considered significant due to its potential for sensitive information disclosure.
How do I fix ZDI-CAN-19279?
To fix ZDI-CAN-19279, ensure that your Delta Electronics InfraSuite Device Master is updated to the latest security patch provided by the vendor.
Can ZDI-CAN-19279 be exploited without authentication?
No, ZDI-CAN-19279 requires authentication; however, the authentication mechanism can be bypassed.
What type of information can be disclosed by exploiting ZDI-CAN-19279?
Exploiting ZDI-CAN-19279 can lead to the disclosure of sensitive information from the affected Delta Electronics InfraSuite Device Master installations.
Is ZDI-CAN-19279 present in all versions of Delta Electronics InfraSuite Device Master?
ZDI-CAN-19279 affects specific installations of Delta Electronics InfraSuite Device Master, but details on version applicability should be checked with the vendor.