CVE-2024-10456: Delta Electronics Infrasuite Device Master

Critical severity, CVSS 9.8. EPSS: 17.6% chance of exploitation in the next 30 days.

Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication.

Affected products

  • Delta Electronics Infrasuite Device Master: up to and including 1.0.12
  • Deltaww Infrasuite Device Master: up to and including 1.0.12

Published 2024-10-30. Last modified 2026-06-17.