CVE-2023-1143
- EPSS 0.14%
- Veröffentlicht 27.03.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:38:32
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could allow an attacker to remotely execute arbitrary code.
CVE-2023-1142
- EPSS 0.04%
- Veröffentlicht 27.03.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:38:32
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation.
CVE-2023-1138
- EPSS 0.1%
- Veröffentlicht 27.03.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 07:38:31
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could allow an attacker to retrieve Gateway configuration files to obtain plaintext credentials.
CVE-2023-1141
- EPSS 0.91%
- Veröffentlicht 27.03.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 07:38:32
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could allow an attacker to inject arbitrary commands, which could result in remote code execution.
CVE-2023-1140
- EPSS 0.7%
- Veröffentlicht 27.03.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 07:38:32
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administrator.
CVE-2023-1139
- EPSS 1.01%
- Veröffentlicht 27.03.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 07:38:32
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway service, which could allow deserialization of requests prior to authentication, resulting in remote code e...
CVE-2023-1137
- EPSS 0.1%
- Veröffentlicht 27.03.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 07:38:31
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation.
CVE-2023-1136
- EPSS 0.03%
- Veröffentlicht 27.03.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 07:38:31
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass.
CVE-2023-1135
- EPSS 0.03%
- Veröffentlicht 27.03.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 07:38:31
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in local privilege escalation.
CVE-2023-1134
- EPSS 0.1%
- Veröffentlicht 27.03.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 07:38:31
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to read local files, disclose plaintext credentials, and escalate privileges.