CVE-2023-1145: Deltaww Infrasuite Device Master
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.
Affected products
- Deltaww Infrasuite Device Master: before 1.0.5 (fixed in 1.0.5)
Published 2023-03-27. Last modified 2026-06-17.