ZDI-CAN-21707: ZDI-23-1752: Delta Electronics InfraSuite Device Master UploadMedia Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics InfraSuite Device Master. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-46690.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21707?
The CVSS rating of ZDI-CAN-21707 is 8.8, indicating a high severity level.
How do I fix ZDI-CAN-21707?
To fix ZDI-CAN-21707, apply the latest security updates provided by Delta Electronics for InfraSuite Device Master.
Who is affected by ZDI-CAN-21707?
ZDI-CAN-21707 affects installations of Delta Electronics InfraSuite Device Master that require authentication for exploitation.
What type of attack does ZDI-CAN-21707 enable?
ZDI-CAN-21707 allows remote attackers to execute arbitrary code on affected installations.
Is authentication required to exploit ZDI-CAN-21707?
Yes, authentication is required to exploit the ZDI-CAN-21707 vulnerability.