First published: Mon Mar 27 2023(Updated: )
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Infrasuite Device Master | <1.0.5 | |
Delta Electronics Versions prior to 1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1133 is a vulnerability found in Delta Electronics InfraSuite Device Master versions prior to 1.0.5, where the Device-status service listens on port 10100/ UDP by default and accepts unverified UDP packets, which could allow remote attackers to execute arbitrary code.
CVE-2023-1133 has a severity score of 9.8, which is considered critical.
The affected software is Delta Electronics InfraSuite Device Master with versions prior to 1.0.5.
The CWE category of CVE-2023-1133 is CWE-502: Deserialization of Untrusted Data.
To fix CVE-2023-1133, it is recommended to update Delta Electronics InfraSuite Device Master to version 1.0.5 or later.