CVE-2023-34347
CRITICALDeltaww Infrasuite Device Master < 1.0.7 - Insecure Deserialization
Title source: ruleDescription
Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code.
Scores
CVSS v3
9.8
EPSS
0.0012
EPSS Percentile
31.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
deltaww/infrasuite_device_master
< 1.0.7
Timeline
Published
Jul 10, 2023
Tracked Since
Feb 18, 2026