CVE-2022-41657

CRITICAL

Delta Electronics InfraSuite Device Master <00.00.01a - Code Injection

Title source: llm
STIX 2.1

Description

Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could create arbitrary files, which could be used in API operations and could ultimately result in remote code execution.

References (1)

Core 1
Core References
Patch, Third Party Advisory, US Government Resource government-resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-07

Scores

CVSS v3 9.8
EPSS 0.0347
EPSS Percentile 87.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
deltaww/infrasuite_device_master < 00.00.02a
Published Oct 31, 2022
Tracked Since Feb 18, 2026