Delta Electronics InfraSuite Device Master Deserialization of Untrusted Data
Vulnerability Description
Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10456
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Simon Humbert of Trend Micro reported this vulnerability to CISA.
More from Delta Electronics
View All →Affected Vendor
Delta Electronics
View all reports →