Lucene search

K
nvd[email protected]NVD:CVE-2023-0444
HistoryJan 26, 2023 - 9:18 p.m.

CVE-2023-0444

2023-01-2621:18:08
web.nvd.nist.gov
2
vulnerability
privilege escalation
delta electronics infrasuite device master 00.00.02a
read only user
administrator
unauthorized access

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

43.2%

A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user ‘User’, which is in the ‘Read Only User’ group, can view the password of another default user ‘Administrator’, which is in the ‘Administrator’ group. This allows any lower privileged user to log in as an administrator.

Affected configurations

Nvd
Node
deltawwinfrasuite_device_masterMatch00.00.02a
VendorProductVersionCPE
deltawwinfrasuite_device_master00.00.02acpe:2.3:a:deltaww:infrasuite_device_master:00.00.02a:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

43.2%

Related for NVD:CVE-2023-0444