CVE-2022-41688
Last modified
CVE-2022-41688 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. An attacker could provide malicious serialized objects that could run these functions without authentication to create a new user and add them to the administrator group. . EPSS estimates a 0.64% chance of exploitation in the next 30 days.
Description
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. An attacker could provide malicious serialized objects that could run these functions without authentication to create a new user and add them to the administrator group.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Deltaww | Infrasuite Device Master | < 00.00.02a |
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-07Patch, Third Party Advisory, US Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-07Patch, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-41688?
How severe is CVE-2022-41688?
How do I fix CVE-2022-41688?
Are you affected by CVE-2022-41688?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
