← Vulnerability feed

Vulnerability record · CVE-2023-1133 · published 27 March 2023

CVE-2023-1133: Delta InfraSuite Device Master UDP deserialization RCE

Deltaww · Infrasuite Device Master

Delta Electronics InfraSuite Device Master versions before 1.0.5 run a Device-status service on UDP port 10100 that deserializes unverified packet content. Because the data is deserialized without validation, an unauthenticated remote attacker can execute arbitrary code. This is a critical pre-auth flaw in an industrial management product.

9.8 CVSS 3.1 Critical EPSS 50% · top 1.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, and remote code execution in an industrial management product.

What it is

Delta Electronics InfraSuite Device Master versions before 1.0.5 run a Device-status service on UDP port 10100 that deserializes unverified packet content. Because the data is deserialized without validation, an unauthenticated remote attacker can execute arbitrary code. This is a critical pre-auth flaw in an industrial management product.

Impact

An attacker gains remote code execution on the host running InfraSuite Device Master, with high impact to confidentiality, integrity and availability. This can lead to full compromise of the management server and any connected industrial devices.

Attack surface

Reachable over the network via UDP port 10100, which the Device-status service listens on by default. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.5005, 98.8th percentile), and a public Packet Storm reference exists, indicating exploit interest but not confirmed in-the-wild use.

What to do

  • Upgrade InfraSuite Device Master to version 1.0.5 or later.
  • Block or restrict inbound UDP port 10100 to trusted hosts only.
  • Segment the InfraSuite Device Master host from untrusted networks and the internet.
  • Monitor for unexpected outbound connections or process creation on the host.
  • Apply vendor guidance from CISA ICS advisory ICSA-23-080-02.

Detection

  • Monitor network traffic for UDP port 10100 packets from unexpected sources.
  • Alert on unusual child processes spawned by the Device Master service.
  • Inspect host logs for deserialization errors or crashes in the Device-status service.
  • Watch for outbound connections from the InfraSuite host to unknown destinations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-1133 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-47207Deltaww infrasuite device master deserialization of untrusted data vulnerabilityIn Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local admi…EPSS 17%9.8CVE-2023-39226Deltaww infrasuite device master vulnerabilityIn Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute arbitrary code throu…EPSS 1.2%9.8CVE-2023-30765Deltaww infrasuite device master improper privilege management vulnerability​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege …EPSS 2.0%9.8CVE-2023-34347Deltaww infrasuite device master deserialization of untrusted data vulnerability​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remo…EPSS 0.95%9.8CVE-2023-1142Deltaww infrasuite device master path traversal vulnerabilityIn Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and …EPSS 1.1%9.8CVE-2023-1140Deltaww infrasuite device master missing authentication for critical function vulnerabilityDelta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated re…EPSS 1.1%9.8CVE-2022-41657Deltaww infrasuite device master path traversal vulnerabilityDelta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in fil…EPSS 21%9.8CVE-2022-41772Deltaww infrasuite device master path traversal vulnerabilityDelta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This pa…EPSS 25%

Source: NIST National Vulnerability Database (record CVE-2023-1133), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.