CVE-2022-41776 affects Delta Electronics InfraSuite Device Master versions 00.00.01a and earlier, allowing unauthenticated attackers to invoke the WriteConfiguration method. This critical flaw, rated 7.5 HIGH on CVSS, enables attackers to modify user configuration files, including UserListInfo.xml, potentially leading to administrative password changes. While no active exploitation, public exploits, or significant community discussion have been observed, the vulnerability presents a direct and unauthenticated path to compromise user credentials.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 00.00.02aCPE matchmatch criteria | cpe:2.3:a:deltaww:infrasuite_device_master:*:*:*:*:*:*:*:* | ||
>= 0, <= 00.00.01aCPE match | cpe:2.3:a:deltaww:infrasuite_device_master:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.