CVE-2023-1133 – CVE-2023-1133
https://notcve.org/view.php?id=CVE-2023-1133
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics InfraSuite Device Master. Authentication is not required to exploit this vulnerability. The specific flaw exists within the installed instance of Apache ActiveMQ, which utilizes an outdated version of the JDK. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. • http://packetstormsecurity.com/files/172799/Delta-Electronics-InfraSuite-Device-Master-Deserialization.html https://www.cisa.gov/news-events/ics-advisories/icsa-23-080-02 https://www.zerodayinitiative.com/advisories/ZDI-23-672 https://attackerkb.com/topics/owl4Xz8fKW/cve-2023-1133 • CWE-502: Deserialization of Untrusted Data •
CVE-2023-0444
https://notcve.org/view.php?id=CVE-2023-0444
A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Only User' group, can view the password of another default user 'Administrator', which is in the 'Administrator' group. This allows any lower privileged user to log in as an administrator. Existe una vulnerabilidad de escalada de privilegios en Delta Electronics InfraSuite Device Master 00.00.02a. Un usuario predeterminado 'Usuario', que está en el grupo 'Usuario de solo lectura', puede ver la contraseña de otro usuario predeterminado 'Administrador', que está en el grupo 'Administrador'. • https://www.tenable.com/security/research/tra-2023-4 •
CVE-2022-41629 – Delta Industrial Automation InfraSuite Device Master APRunning Missing Authentication Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2022-41629
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could allow an attacker to retrieve any file from the “RunningConfigs” directory. The attacker could then view and modify configuration files such as UserListInfo.xml, which would allow them to see existing administrative passwords. Las versiones 00.00.01a y anteriores de Delta Electronics InfraSuite Device Master permiten que usuarios no autenticados accedan al endpoint de ejecución, lo que podría permitir a un atacante recuperar cualquier archivo del directorio ""RunningConfigs"". Luego, el atacante podría ver y modificar archivos de configuración como UserListInfo.xml, lo que le permitiría ver las contraseñas administrativas existentes. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Delta Industrial Automation InfraSuite Device Master. • https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-07 • CWE-306: Missing Authentication for Critical Function •
CVE-2022-40202 – Delta Industrial Automation InfraSuite Device Master ExeCommandInCommandLineMode Missing Authentication Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2022-40202
The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker could provide malicious serialized objects which, when deserialized, could activate an opcode for a backup scheduling function without authentication. This function allows the user to designate all function arguments and the file to be executed. This could allow the attacker to start any new process and achieve remote code execution. La función de copia de seguridad de la base de datos en Delta Electronics InfraSuite Device Master versiones 00.00.01a y anteriores carece de autenticación adecuada. • https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-07 • CWE-306: Missing Authentication for Critical Function •
CVE-2022-38142 – Delta Industrial Automation InfraSuite Device Master Device-DataCollect Service Deserialization of Untrusted Data Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2022-38142
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization. Delta Electronics InfraSuite Device Master versiones 00.00.01a y anteriores deserializan los datos proporcionados por el usuario a través del puerto de servicio Device-Gateway sin la verificación adecuada. Un atacante podría proporcionar objetos serializados maliciosos para ejecutar código arbitrario tras la deserialización. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Industrial Automation InfraSuite Device Master. • https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-07 • CWE-502: Deserialization of Untrusted Data •