Lucene search

K
cvelistIcscertCVELIST:CVE-2023-47279
HistoryNov 30, 2023 - 10:12 p.m.

CVE-2023-47279 Delta Electronics InfraSuite Device Master Path Traversal

2023-11-3022:12:05
CWE-35
icscert
www.cve.org
5
cve-2023-47279
delta electronics
infrasuite
path traversal
udp
user information
plaintext credentials
ntlm relaying

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

43.6%

In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information through a single UDP packet, obtain plaintext credentials, or perform NTLM relaying.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "InfraSuite Device Master",
    "vendor": "Delta Electronics",
    "versions": [
      {
        "lessThanOrEqual": "1.0.7",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

43.6%

Related for CVELIST:CVE-2023-47279