"value":"Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-502 Deserialization of Untrusted Data",
"value":"<span style=\"background-color: rgb(255, 255, 255);\">Delta Electronics states that this issue was fixed by version 1.0.13 released in October 2024. Delta recommends updating to </span><a target=\"_blank\" rel=\"nofollow\" href=\"https://datacenter-softwarecenter.deltaww.com/Download/UPS/Software/InfraSuite_Device_Master_1.0.13.exe\">version 1.0.13</a><span style=\"background-color: rgb(255, 255, 255);\"> or later.</span>\n\n<br>"
}
],
"value":"Delta Electronics states that this issue was fixed by version 1.0.13 released in October 2024. Delta recommends updating to version 1.0.13 https://datacenter-softwarecenter.deltaww.com/Download/UPS/Software/InfraSuite_Device_Master_1.0.13.exe \u00a0or later."
}
],
"credits":[
{
"lang":"en",
"value":"Simon Humbert of Trend Micro reported this vulnerability to CISA."