Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Delta Electronics states that this issue was fixed by version 1.0.13 released in October 2024. Delta recommends updating to version 1.0.13 https://datacenter-softwarecenter.deltaww.com/Download/UPS/Software/InfraSuite_Device_Master_1.0.13.exe or later.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-33131 | Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication. |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 30 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Deltaww
Deltaww infrasuite Device Master |
|
| CPEs | cpe:2.3:a:deltaww:infrasuite_device_master:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Deltaww
Deltaww infrasuite Device Master |
|
| Metrics |
ssvc
|
Wed, 30 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication. | |
| Title | Delta Electronics InfraSuite Device Master Deserialization of Untrusted Data | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-10-30T18:15:45.431Z
Reserved: 2024-10-28T14:05:02.628Z
Link: CVE-2024-10456
Updated: 2024-10-30T18:15:40.044Z
Status : Deferred
Published: 2024-10-30T18:15:05.123
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-10456
No data.
OpenCVE Enrichment
No data.
EUVD