Lucene search

K
zdiKimiyaZDI-22-1483
HistoryOct 27, 2022 - 12:00 a.m.

Delta Industrial Automation InfraSuite Device Master CheckLoadingStartupConfig Directory Traversal Remote Code Execution Vulnerability

2022-10-2700:00:00
kimiya
www.zerodayinitiative.com
12
delta industrial automation
infrasuite
device master
checkloadingstartupconfig
directory traversal
remote code execution

EPSS

0.004

Percentile

73.0%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Industrial Automation InfraSuite Device Master. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CheckLoadingStartupConfig function. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of an administrator.

EPSS

0.004

Percentile

73.0%

Related for ZDI-22-1483