CVE-2023-1133: Critical severity delta electronics infrasuite device master vulnerability
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-1133?
CVE-2023-1133 is a vulnerability found in Delta Electronics InfraSuite Device Master versions prior to 1.0.5, where the Device-status service listens on port 10100/ UDP by default and accepts unverified UDP packets, which could allow remote attackers to execute arbitrary code.
How severe is CVE-2023-1133?
CVE-2023-1133 has a severity score of 9.8, which is considered critical.
What is the affected software and version of CVE-2023-1133?
The affected software is Delta Electronics InfraSuite Device Master with versions prior to 1.0.5.
What is the CWE category of CVE-2023-1133?
The CWE category of CVE-2023-1133 is CWE-502: Deserialization of Untrusted Data.
How can I fix CVE-2023-1133?
To fix CVE-2023-1133, it is recommended to update Delta Electronics InfraSuite Device Master to version 1.0.5 or later.