Vulnerability record · CVE-2023-1133 · published 27 March 2023
CVE-2023-1133: Delta InfraSuite Device Master UDP deserialization RCE
Deltaww · Infrasuite Device Master
Delta Electronics InfraSuite Device Master versions before 1.0.5 run a Device-status service on UDP port 10100 that deserializes unverified packet content. Because the data is deserialized without validation, an unauthenticated remote attacker can execute arbitrary code. This is a critical pre-auth flaw in an industrial management product.
Description
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and remote code execution in an industrial management product.
What it is
Delta Electronics InfraSuite Device Master versions before 1.0.5 run a Device-status service on UDP port 10100 that deserializes unverified packet content. Because the data is deserialized without validation, an unauthenticated remote attacker can execute arbitrary code. This is a critical pre-auth flaw in an industrial management product.
Impact
An attacker gains remote code execution on the host running InfraSuite Device Master, with high impact to confidentiality, integrity and availability. This can lead to full compromise of the management server and any connected industrial devices.
Attack surface
Reachable over the network via UDP port 10100, which the Device-status service listens on by default. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.5005, 98.8th percentile), and a public Packet Storm reference exists, indicating exploit interest but not confirmed in-the-wild use.
What to do
- Upgrade InfraSuite Device Master to version 1.0.5 or later.
- Block or restrict inbound UDP port 10100 to trusted hosts only.
- Segment the InfraSuite Device Master host from untrusted networks and the internet.
- Monitor for unexpected outbound connections or process creation on the host.
- Apply vendor guidance from CISA ICS advisory ICSA-23-080-02.
Detection
- Monitor network traffic for UDP port 10100 packets from unexpected sources.
- Alert on unusual child processes spawned by the Device Master service.
- Inspect host logs for deserialization errors or crashes in the Device-status service.
- Watch for outbound connections from the InfraSuite host to unknown destinations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/172799/Delta-Electronics-InfraSuite-Device-Master-Deserialization.html | |
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-080-02 | Third Party AdvisoryUS Government Resource |
| http://packetstormsecurity.com/files/172799/Delta-Electronics-InfraSuite-Device-Master-Deserialization.html | |
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-080-02 | Third Party AdvisoryUS Government Resource |
Track CVE-2023-1133 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-1133), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.