← Vulnerability feed

Vulnerability record · CVE-2022-41657 · published 31 October 2022

CVE-2022-41657: Deltaww infrasuite device master path traversal vulnerability

Deltaww · Infrasuite Device Master

Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could create arbitrary files, which could be used in API operations and could ultimately result in remote code execution.

9.8 CVSS 3.1 Critical EPSS 21% · top 2.5% CWE-22 · Path traversal
9.8CVSS 3.1 base score
21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could create arbitrary files, which could be used in API operations and could ultimately result in remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-07 PatchThird Party AdvisoryUS Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-07 PatchThird Party AdvisoryUS Government Resource

Track CVE-2022-41657 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-47207Deltaww infrasuite device master deserialization of untrusted data vulnerabilityIn Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local admi…EPSS 17%9.8CVE-2023-39226Deltaww infrasuite device master vulnerabilityIn Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute arbitrary code throu…EPSS 1.2%9.8CVE-2023-30765Deltaww infrasuite device master improper privilege management vulnerability​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege …EPSS 2.0%9.8CVE-2023-34347Deltaww infrasuite device master deserialization of untrusted data vulnerability​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remo…EPSS 0.95%9.8CVE-2023-1142Deltaww infrasuite device master path traversal vulnerabilityIn Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and …EPSS 1.1%9.8CVE-2023-1133Delta InfraSuite Device Master UDP deserialization RCEDelta Electronics InfraSuite Device Master versions before 1.0.5 run a Device-status service on UDP port 10100 that deserializes unverified packet co…EPSS 50%analysed9.8CVE-2023-1140Deltaww infrasuite device master missing authentication for critical function vulnerabilityDelta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated re…EPSS 1.1%9.8CVE-2022-41772Deltaww infrasuite device master path traversal vulnerabilityDelta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This pa…EPSS 25%

Source: NIST National Vulnerability Database (record CVE-2022-41657), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.