CVE-2022-1098: Delta Electronics DIAEnergie Uncontrolledly Search Path Element
Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default Permissions vulnerability of 4.2.2 above, this makes it possible for an attacker to escalate privileges
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for Delta Electronics DIAEnergie?
The vulnerability ID for Delta Electronics DIAEnergie is CVE-2022-1098.
What is the severity level of CVE-2022-1098?
The severity level of CVE-2022-1098 is high with a score of 7.8.
How can an attacker exploit CVE-2022-1098?
An attacker can exploit CVE-2022-1098 by leveraging a DLL hijacking condition combined with the Incorrect Default Permissions vulnerability to escalate privileges.
Which versions of Delta Electronics DIAEnergie are affected by CVE-2022-1098?
All versions of Delta Electronics DIAEnergie prior to 1.8.02.004 are affected by CVE-2022-1098.
How can I fix CVE-2022-1098 in Delta Electronics DIAEnergie?
To fix CVE-2022-1098 in Delta Electronics DIAEnergie, it is recommended to update to version 1.8.02.004 or later.