Vulnerability Details CVE-2022-38142
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.019
EPSS Ranking 82.5%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-38142
-
cpe:2.3:a:deltaww:infrasuite_device_master:-
-
cpe:2.3:a:deltaww:infrasuite_device_master:00.00.01a