CVE-2023-1133
CRITICALDelta Electronics InfraSuite Device Master < 1.0.5 - Remote Code Execution via UDP Deserialization
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-1133.
PoCs published by Anonymous, Shelby Pace, including Metasploit module exploits/windows/misc/delta_electronics_infrasuite_deserialization.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated .NET deserialization vulnerability in Delta Electronics InfraSuite Device Master versions below 1.0.5. It leverages the 'ParseUDPPacket()' method to execute arbitrary commands via crafted UDP packets containing malicious serialized data.
Description
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.
Exploits (1)
This Metasploit module exploits an unauthenticated .NET deserialization vulnerability in Delta Electronics InfraSuite Device Master versions below 1.0.5. It leverages the 'ParseUDPPacket()' method to execute arbitrary commands via crafted UDP packets containing malicious serialized data.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H