TCP: Delta Electronics InfraSuite Device Master CheckLoadingStartupConfig Directory Traversal
This signature detects attempts to exploit a known vulnerability against Delta Electronics InfraSuite Device Master CheckLoadingStartupConfig. A successful attack can lead to directory traversal and arbitrary code execution.
Extended Description
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This path traversal could result in remote code execution.
Affected Products
Deltaww infrasuite_device_master
References
CVE: CVE-2022-41657
URL: http://www.zerodayinitiative.com/advisories/ZDI-22-1483/ http://www.zerodayinitiative.com/advisories/ZDI-22-1481/ http://www.zerodayinitiative.com/advisories/ZDI-22-1479/ https://www.cisa.gov/news-events/ics-advisories/icsa-22-298-07 http://www.zerodayinitiative.com/advisories/ZDI-22-1482/
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vsrx-19.2
srx-19.3
Deltaww