Skip to content
Threat Feed
high advisory

Privilege Escalation Vulnerability in Delta Electronics Infrasuite Device Master

CVE-2023-30765 is a privilege escalation vulnerability in Delta Electronics Infrasuite Device Master versions prior to 1.0.7 that allows an attacker to add arbitrary users to the administrator group.

CVE search metadata

CVE search record: CVE-2023-30765. Severity: high. CVSS: 8.8. EPSS: 1.97%. KEV: no. Product: Infrasuite Device Master (< 1.0.7). Brief: Privilege Escalation Vulnerability in Delta Electronics Infrasuite Device Master. Brief link: https://feed.craftedsignal.io/briefs/2026-08-delta-infrasuite-privesc/

Delta Electronics Infrasuite Device Master versions prior to 1.0.7 are susceptible to a privilege escalation vulnerability tracked as CVE-2023-30765 (ZDI-23-905). This vulnerability allows an authenticated attacker to perform an unauthorized modification of user group memberships, specifically enabling the escalation of a standard user account to the administrator group. The discovery of this flaw, attributed to Piotr Bazydlo, highlights a critical security gap in access control management within the Infrasuite Device Master platform. The availability of a public functional exploit script on repository platforms as of August 2026 significantly increases the likelihood of exploitation attempts against unpatched infrastructure. Security teams should prioritize patching instances to version 1.0.7 or higher to mitigate unauthorized administrative access.

Impact

Successful exploitation of CVE-2023-30765 allows an attacker to gain full administrative control over the targeted Delta Electronics Infrasuite Device Master instance. This leads to complete system compromise, unauthorized access to sensitive operational data, and potential manipulation of integrated facility management hardware. Given the product's role in infrastructure management, impact includes potential disruption to critical facility services.

Recommendation

Prioritize the upgrade of all internet-facing Delta Electronics Infrasuite Device Master instances to version 1.0.7 or later. Restrict network access to the web management interface, ensuring it is not exposed to the public internet. Audit existing administrator groups for unauthorized users added through non-standard account creation processes. Monitor web server logs for suspicious POST requests targeting user management endpoints consistent with the documented exploit tool usage.


Immediate actions

Upgrade Delta Electronics Infrasuite Device Master to 1.0.7 or later.

IT Operations 48h

Mitigations

Restrict network access to management interfaces.

immediate IT Operations

CVE-2023-30765