CVE-2023-0444

HIGH

Delta Electronics InfraSuite Device Master 00.00.02a - Privilege Escalation via Default User Password Exposure

Title source: llm
STIX 2.1

Description

A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Only User' group, can view the password of another default user 'Administrator', which is in the 'Administrator' group. This allows any lower privileged user to log in as an administrator.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0040
EPSS Percentile 60.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (1)
deltaww/infrasuite_device_master 00.00.02a
Published Jan 26, 2023
Tracked Since Feb 18, 2026