CVE-2022-0988: Delta Electronics DIAEnergie CLEARTEXT Transmission of Sensitive Information
Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is CVE-2022-0988?
CVE-2022-0988 is a vulnerability in Delta Electronics DIAEnergie (Version 1.7.5 and prior) that allows cleartext transmission of information over HTTP.
How does CVE-2022-0988 affect Delta Electronics DIAEnergie?
CVE-2022-0988 allows an attacker to remotely read transmitted information between the client and the product in Delta Electronics DIAEnergie (Version 1.7.5 and prior).
What is the severity of CVE-2022-0988?
CVE-2022-0988 has a severity rating of high (7.5).
How can I fix CVE-2022-0988?
To fix CVE-2022-0988, upgrade Delta Electronics DIAEnergie to a version higher than 1.7.5 or apply the necessary patches provided by the vendor.
Where can I find more information about CVE-2022-0988?
You can find more information about CVE-2022-0988 in the advisory published by CISA at https://www.cisa.gov/uscert/ics/advisories/icsa-21-238-03.