Cyber Resilience

CVE-2023-1138

Deltaww Infrasuite Device Master ≤ 1.0.5

Published
27 March 2023
Modified
21 November 2024
CVSS Score v3.1 7.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0057 44th percentile
Risk Priority 58 floored blend · peak EPSS

Summary

CVE-2023-1138 is a high-severity an unspecified weakness vulnerability in Deltaww Infrasuite Device Master. Its CVSS base score is 7.5 (High).

Operationally, ranked at the 44th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could allow an attacker to retrieve Gateway configuration files to obtain plaintext credentials.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-46690Same product: Deltaww Infrasuite Device Master
CVE-2023-1140Same product: Deltaww Infrasuite Device Master
CVE-2023-1134Same product: Deltaww Infrasuite Device Master
CVE-2023-1142Same product: Deltaww Infrasuite Device Master
CVE-2023-1136Same product: Deltaww Infrasuite Device Master
CVE-2023-1137Same product: Deltaww Infrasuite Device Master
CVE-2023-1145Same product: Deltaww Infrasuite Device Master
CVE-2023-34316Same product: Deltaww Infrasuite Device Master
CVE-2023-1144Same product: Deltaww Infrasuite Device Master
CVE-2023-47207Same product: Deltaww Infrasuite Device Master

Affected Assets

deltaww
infrasuite device master
≤ 1.0.5

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References