APP: Delta Electronics InfraSuite Device Master Device-DataCollect Insecure Deserialization
This signature detects attempts to exploit a known vulnerability against Delta Electronics InfraSuite Device Master Device-DataCollec. A successful attack can lead to arbitrary code execution.
Extended Description
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.
Affected Products
Deltaww infrasuite_device_master
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Deltaww