ZDI-CAN-21859: ZDI-23-1755: Delta Electronics InfraSuite Device Master RunScript Exposed Dangerous Method Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics InfraSuite Device Master. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2023-39226.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21859?
ZDI-CAN-21859 has been assigned a CVSS rating of 9.8, indicating a critical severity level.
How do I fix ZDI-CAN-21859?
To fix ZDI-CAN-21859, ensure that you update Delta Electronics InfraSuite Device Master to the latest secured version provided by the vendor.
Who is affected by ZDI-CAN-21859?
ZDI-CAN-21859 affects installations of Delta Electronics InfraSuite Device Master software.
Can ZDI-CAN-21859 be exploited remotely?
Yes, ZDI-CAN-21859 allows remote attackers to execute arbitrary code without the need for authentication.
What is the nature of the threat posed by ZDI-CAN-21859?
ZDI-CAN-21859 presents a significant threat as it enables remote code execution on vulnerable systems.