ZDI-CAN-24594: ZDI-24-1457: Delta Electronics InfraSuite Device Master _gExtraInfo Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Nov 6, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics InfraSuite Device Master. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-10456.
Affected Software
1 affected component
Delta Electronics InfraSuite Device Master
Event History
Nov 6, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-24594?
ZDI-CAN-24594 has a CVSS rating of 9.8, indicating it is a critical vulnerability.
2
How do I fix ZDI-CAN-24594?
To mitigate ZDI-CAN-24594, update to the latest version of Delta Electronics InfraSuite Device Master as recommended by the vendor.
3
What type of exploitation does ZDI-CAN-24594 allow?
ZDI-CAN-24594 allows remote attackers to execute arbitrary code without requiring authentication.
4
Which software is affected by ZDI-CAN-24594?
ZDI-CAN-24594 affects Delta Electronics InfraSuite Device Master.
5
Is authentication required to exploit ZDI-CAN-24594?
No, authentication is not required to exploit ZDI-CAN-24594.