First published: Tue Mar 22 2022(Updated: )
Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
DIAEnergie | <=1.7.5 | |
DIAEnergie | <1.9 | 1.9 |
Delta Electronics has released an updated version of DIAEnergie and recommends users install v1.8.0 and later on all affected systems.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0988 is a vulnerability in Delta Electronics DIAEnergie (Version 1.7.5 and prior) that allows cleartext transmission of information over HTTP.
CVE-2022-0988 allows an attacker to remotely read transmitted information between the client and the product in Delta Electronics DIAEnergie (Version 1.7.5 and prior).
CVE-2022-0988 has a severity rating of high (7.5).
To fix CVE-2022-0988, upgrade Delta Electronics DIAEnergie to a version higher than 1.7.5 or apply the necessary patches provided by the vendor.
You can find more information about CVE-2022-0988 in the advisory published by CISA at https://www.cisa.gov/uscert/ics/advisories/icsa-21-238-03.