PT-2023-16275 · Delta Electronics · Infrasuite Device Master

Publicado

2023-01-24

·

Atualizado

2023-02-06

·

CVE-2023-0444

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Delta Electronics InfraSuite Device Master version 00.00.02a
Description A privilege escalation issue exists, allowing a lower-privileged user to view the password of a higher-privileged user. Specifically, the default user 'User' in the 'Read Only User' group can access the password of the default 'Administrator' user in the 'Administrator' group. This enables any lower-privileged user to log in as an administrator.
Recommendations For Delta Electronics InfraSuite Device Master version 00.00.02a, consider changing the default passwords of all users, especially the 'Administrator' user, and restrict access to user password information to prevent unauthorized viewing. As a temporary workaround, restrict the privileges of the 'Read Only User' group to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-0444

Produtos afetados

Infrasuite Device Master