APP: Delta Electronics InfraSuite Device Master ActiveMQ Insecure Deserialization
This signature detects attempts to exploit a known vulnerability against Delta Electronics InfraSuite Device Master ActiveMQ. A successful attack can lead to arbitrary code execution.
Extended Description
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.
Affected Products
Deltaww infrasuite_device_master
References
CVE: CVE-2023-1133
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vsrx-19.2
srx-19.3
Deltaww