PT-2023-16275 · Delta Electronics · Infrasuite Device Master
Publicado
2023-01-24
·
Atualizado
2023-02-06
·
CVE-2023-0444
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Delta Electronics InfraSuite Device Master version 00.00.02a
Description
A privilege escalation issue exists, allowing a lower-privileged user to view the password of a higher-privileged user. Specifically, the default user 'User' in the 'Read Only User' group can access the password of the default 'Administrator' user in the 'Administrator' group. This enables any lower-privileged user to log in as an administrator.
Recommendations
For Delta Electronics InfraSuite Device Master version 00.00.02a, consider changing the default passwords of all users, especially the 'Administrator' user, and restrict access to user password information to prevent unauthorized viewing. As a temporary workaround, restrict the privileges of the 'Read Only User' group to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Infrasuite Device Master