CVE-2023-1142

HIGH

InfraSuite Device Master < 1.0.5 - Path Traversal and Privilege Escalation via URL Decoding

Title source: llm
STIX 2.1

Description

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-080-02

Scores

CVSS v3 7.5
EPSS 0.0047
EPSS Percentile 64.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
deltaww/infrasuite_device_master < 1.0.5
Published Mar 27, 2023
Tracked Since Feb 18, 2026