Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Delta Electronics InfraSuite Device Master Deserialization of Untrusted Data
Vulnerability Description
Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Delta Electronics InfraSuite Device Master 代码问题漏洞
Vulnerability Description
Delta Electronics InfraSuite Device Master是中国台达电子(Delta Electronics)公司的用于简化和自动化关键设备监控的设备。 Delta Electronics InfraSuite Device Master 1.0.12及之前版本存在代码问题漏洞,该漏洞源于受到针对设备网关的反序列化漏洞的影响,允许在身份验证之前反序列化任意.NET对象,从而导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A