TCP: Delta Electronics InfraSuite Device Master CheckLoadingStartupConfig Directory Traversal

This signature detects attempts to exploit a known vulnerability against Delta Electronics InfraSuite Device Master CheckLoadingStartupConfig. A successful attack can lead to directory traversal and arbitrary code execution.

Extended Description

Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This path traversal could result in remote code execution.

Affected Products

Deltaww infrasuite_device_master

Short Name
TCP:C2S:DELTA-INFRA-DM-CFG-DIR
Severity
Major
Recommended
False
Recommended Action
Drop
Category
TCP
Keywords
CVE-2022-41657 CVE-2022-41772 CheckLoadingStartupConfig Delta Device Directory Electronics InfraSuite Master Traversal
Release Date
11/22/2022
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3650
Port
TCP/3100
False Positive
Unknown
Vendors

Deltaww

Found a potential security threat?