跳转到帖子

Delta Electronics InfraSuite Device Master Deserialization

recommended_posts

发布于
  • Members

Delta Electronics InfraSuite Device Master Deserialization

Disclosed
05/17/2023
Created
06/08/2023

Description

Delta Electronics InfraSuite Device Master versions below v1.0.5 have an unauthenticated .NET deserialization vulnerability within the 'ParseUDPPacket()' method of the 'Device-Gateway-Status' process. The 'ParseUDPPacket()' method reads user-controlled packet data and eventually calls 'BinaryFormatter.Deserialize()' on what it determines to be the packet header without appropriate validation, leading to unauthenticated code execution as the user running the 'Device-Gateway-Status' process.

Author(s)

  • Anonymous
  • Shelby Pace

Platform

Windows

Architectures

cmd, x86, x64

Development

  • Source Code
  • History
  • 查看数 696
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…