Lucene search

K
cveTenableCVE-2023-0444
HistoryJan 26, 2023 - 9:18 p.m.

CVE-2023-0444

2023-01-2621:18:08
tenable
web.nvd.nist.gov
30
cve-2023-0444
delta electronics
infrasuite device master
privilege escalation
user
password
administrator
vulnerability

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

43.2%

A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user ‘User’, which is in the ‘Read Only User’ group, can view the password of another default user ‘Administrator’, which is in the ‘Administrator’ group. This allows any lower privileged user to log in as an administrator.

Affected configurations

Nvd
Node
deltawwinfrasuite_device_masterMatch00.00.02a
VendorProductVersionCPE
deltawwinfrasuite_device_master00.00.02acpe:2.3:a:deltaww:infrasuite_device_master:00.00.02a:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Delta Electronics InfraSuite Device Master 00.00.02a",
    "versions": [
      {
        "version": "Delta Electronics InfraSuite Device Master 00.00.02a",
        "status": "affected"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

43.2%

Related for CVE-2023-0444