Lucene search

K
cveIcscertCVE-2023-47279
HistoryNov 30, 2023 - 11:15 p.m.

CVE-2023-47279

2023-11-3023:15:07
CWE-35
CWE-22
icscert
web.nvd.nist.gov
23
delta electronics
infrasuite
device master
vulnerability
disclosure
udp
plaintext credentials
ntlm relaying
nvd

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

43.6%

In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information through a single UDP packet, obtain plaintext credentials, or perform NTLM relaying.

Affected configurations

Nvd
Node
deltawwinfrasuite_device_masterMatch1.0.7
VendorProductVersionCPE
deltawwinfrasuite_device_master1.0.7cpe:2.3:a:deltaww:infrasuite_device_master:1.0.7:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "InfraSuite Device Master",
    "vendor": "Delta Electronics",
    "versions": [
      {
        "lessThanOrEqual": "1.0.7",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

43.6%

Related for CVE-2023-47279