PT-2023-16275 · Delta Electronics · Infrasuite Device Master

Published

2023-01-24

·

Updated

2023-02-06

·

CVE-2023-0444

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Delta Electronics InfraSuite Device Master version 00.00.02a
Description A privilege escalation issue exists, allowing a lower-privileged user to view the password of a higher-privileged user. Specifically, the default user 'User' in the 'Read Only User' group can access the password of the default 'Administrator' user in the 'Administrator' group. This enables any lower-privileged user to log in as an administrator.
Recommendations For Delta Electronics InfraSuite Device Master version 00.00.02a, consider changing the default passwords of all users, especially the 'Administrator' user, and restrict access to user password information to prevent unauthorized viewing. As a temporary workaround, restrict the privileges of the 'Read Only User' group to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-0444

Affected Products

Infrasuite Device Master