← Vulnerability feed

Vulnerability record · CVE-2023-39226 · published 30 November 2023

CVE-2023-39226: Deltaww infrasuite device master vulnerability

Deltaww · Infrasuite Device Master

In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute arbitrary code through a single UDP packet.

9.8 CVSS 3.1 Critical EPSS 1.2% · top 33.7% CWE-749 · CWE-749
9.8CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute arbitrary code through a single UDP packet.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.cisa.gov/news-events/ics-advisories/icsa-23-331-01 Third Party AdvisoryUS Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-331-01 Third Party AdvisoryUS Government Resource

Track CVE-2023-39226 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-47207Deltaww infrasuite device master deserialization of untrusted data vulnerabilityIn Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local admi…EPSS 17%9.8CVE-2023-30765Deltaww infrasuite device master improper privilege management vulnerability​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege …EPSS 2.0%9.8CVE-2023-34347Deltaww infrasuite device master deserialization of untrusted data vulnerability​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remo…EPSS 0.95%9.8CVE-2023-1142Deltaww infrasuite device master path traversal vulnerabilityIn Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and …EPSS 1.1%9.8CVE-2023-1133Delta InfraSuite Device Master UDP deserialization RCEDelta Electronics InfraSuite Device Master versions before 1.0.5 run a Device-status service on UDP port 10100 that deserializes unverified packet co…EPSS 50%analysed9.8CVE-2023-1140Deltaww infrasuite device master missing authentication for critical function vulnerabilityDelta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated re…EPSS 1.1%9.8CVE-2022-41657Deltaww infrasuite device master path traversal vulnerabilityDelta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in fil…EPSS 21%9.8CVE-2022-41772Deltaww infrasuite device master path traversal vulnerabilityDelta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This pa…EPSS 25%

Source: NIST National Vulnerability Database (record CVE-2023-39226), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.