{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-21T13:41:55.439","vulnerabilities":[{"cve":{"id":"CVE-2022-41776","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2022-10-31T20:15:13.680","lastModified":"2026-06-17T05:03:48.677","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"\nDelta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which could allow an attacker to provide new values for user configuration files such as UserListInfo.xml. This could lead to the changing of administrative passwords.\n\n"},{"lang":"es","value":"Delta Electronics InfraSuite Device Master versiones 00.00.01a y anteriores permiten a usuarios no autenticados activar el método WriteConfiguration, lo que podría permitir a un atacante proporcionar nuevos valores para archivos de configuración de usuario como UserListInfo.xml. Esto podría dar lugar al cambio de contraseñas administrativas.\n"}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"Delta Electronics","product":"InfraSuite Device Master","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"00.00.01a","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-16T15:53:44.615051Z","id":"CVE-2022-41776","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:deltaww:infrasuite_device_master:*:*:*:*:*:*:*:*","versionEndExcluding":"00.00.02a","matchCriteriaId":"0BC08CDF-4EE4-4E6D-AFF0-A4749A91A05D"}]}]}],"references":[{"url":"https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-07","source":"ics-cert@hq.dhs.gov","tags":["Patch","Third Party Advisory","US Government Resource"]},{"url":"https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-07","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory","US Government Resource"]}]}}]}