PT-2023-16275 · Delta Electronics · Infrasuite Device Master
Published
2023-01-24
·
Updated
2023-02-06
·
CVE-2023-0444
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Delta Electronics InfraSuite Device Master version 00.00.02a
Description
A privilege escalation issue exists, allowing a lower-privileged user to view the password of a higher-privileged user. Specifically, the default user 'User' in the 'Read Only User' group can access the password of the default 'Administrator' user in the 'Administrator' group. This enables any lower-privileged user to log in as an administrator.
Recommendations
For Delta Electronics InfraSuite Device Master version 00.00.02a, consider changing the default passwords of all users, especially the 'Administrator' user, and restrict access to user password information to prevent unauthorized viewing. As a temporary workaround, restrict the privileges of the 'Read Only User' group to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Infrasuite Device Master