Lucene search

K
zdiAnonymousZDI-24-440
HistoryMay 13, 2024 - 12:00 a.m.

Delta Electronics InfraSuite Device Master ActiveMQ Deserialization of Untrusted Data Remote Code Execution Vulnerability

2024-05-1300:00:00
Anonymous
www.zerodayinitiative.com
10
delta electronics infrasuite
device master
activemq
remote code execution
apache activemq
tcp port 61616
service account

7.7 High

AI Score

Confidence

High

0.964 High

EPSS

Percentile

99.6%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics InfraSuite Device Master. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Apache ActiveMQ broker, which listens on TCP port 61616 by default. The issue results from the use of a vulnerable version of Apache ActiveMQ. An attacker can leverage this vulnerability to execute code in the context of the service account.