CVE-2024-10456: Delta Electronics InfraSuite Device Master Deserialization of Untrusted Data
Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10456?
CVE-2024-10456 has a medium severity due to the potential for deserialization of arbitrary .NET objects.
How do I fix CVE-2024-10456?
To fix CVE-2024-10456, upgrade Delta Electronics InfraSuite Device Master to version 1.0.12 or later.
What versions of Delta Electronics InfraSuite Device Master are affected by CVE-2024-10456?
All versions prior to 1.0.12 of Delta Electronics InfraSuite Device Master are affected by CVE-2024-10456.
What type of vulnerability is CVE-2024-10456?
CVE-2024-10456 is a deserialization vulnerability that specifically targets the Device-Gateway.
What are the implications of CVE-2024-10456 if exploited?
If CVE-2024-10456 is exploited, an attacker could potentially execute arbitrary code through deserialization prior to authentication.