CVE-2023-1133: Deltaww Infrasuite Device Master

Critical severity, CVSS 9.8. EPSS: 50.1% chance of exploitation in the next 30 days.

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.

Affected products

  • Deltaww Infrasuite Device Master: before 1.0.5 (fixed in 1.0.5)

Published 2023-03-27. Last modified 2026-06-17.