CVE-2023-0444
Published on: Not Yet Published
Last Modified on: 02/06/2023 02:50:00 PM UTC
Certain versions of Infrasuite Device Master from Deltaww contain the following vulnerability:
A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Only User' group, can view the password of another default user 'Administrator', which is in the 'Administrator' group. This allows any lower privileged user to log in as an administrator.
- CVE-2023-0444 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Delta Electronics InfraSuite Device Master Privilege Escalation - Research Advisory | Tenable® | www.tenable.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Exploit/POC from Github
A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user '…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Deltaww | Infrasuite Device Master | 00.00.02a | All | All | All |
- cpe:2.3:a:deltaww:infrasuite_device_master:00.00.02a:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Potentially Critical CVE Detected! CVE-2023-0444 A privilege escalation vulnerability exists in Delta Electronics I… twitter.com/i/web/status/1… | 2023-01-24 20:56:00 |
![]() |
CVE-2023-0444 : A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a… twitter.com/i/web/status/1… | 2023-01-26 21:50:00 |
![]() |
Delta Electronics InfraSuite Device Master privilege escalation | CVE-2023-0444 - redpacketsecurity.com/delta-electron… #CVE… twitter.com/i/web/status/1… | 2023-01-27 10:01:46 |