Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which could allow an attacker to provide new values for user configuration files such as UserListInfo.xml. This could lead to the changing of administrative passwords.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-07 | Patch Third Party Advisory US Government Resource |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: icscert
Published: 2022-10-31T19:48:17.936Z
Updated:
Reserved: 2022-09-29T14:09:27.505Z
Link: CVE-2022-41776
JSON object: View
NVD Information
Status : Modified
Published: 2022-10-31T20:15:13.680
Modified: 2023-11-07T03:52:59.693
Link: CVE-2022-41776
JSON object: View
Redhat Information
No data.
CWE