Vulnerability Details CVE-2022-41778
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.2%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-41778
-
cpe:2.3:a:deltaww:infrasuite_device_master:-
-
cpe:2.3:a:deltaww:infrasuite_device_master:00.00.01a