CVE-2023-1133

CRITICAL

Delta Electronics InfraSuite Device Master < 1.0.5 - Remote Code Execution via UDP Deserialization

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-1133. PoCs published by Anonymous, Shelby Pace, including Metasploit module exploits/windows/misc/delta_electronics_infrasuite_deserialization.

AI-analyzed exploit summary This Metasploit module exploits an unauthenticated .NET deserialization vulnerability in Delta Electronics InfraSuite Device Master versions below 1.0.5. It leverages the 'ParseUDPPacket()' method to execute arbitrary commands via crafted UDP packets containing malicious serialized data.

Description

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Anonymous, Shelby Pace · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/delta_electronics_infrasuite_deserialization.rb

This Metasploit module exploits an unauthenticated .NET deserialization vulnerability in Delta Electronics InfraSuite Device Master versions below 1.0.5. It leverages the 'ParseUDPPacket()' method to execute arbitrary commands via crafted UDP packets containing malicious serialized data.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Delta Electronics InfraSuite Device Master < 1.0.5
No auth needed
Prerequisites: Network access to UDP port 10100 · Target running vulnerable version of InfraSuite Device Master
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.5005
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-502
Status published
Products (1)
deltaww/infrasuite_device_master < 1.0.5
Published Mar 27, 2023
Tracked Since Feb 18, 2026