First published: Fri Apr 01 2022(Updated: )
Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default Permissions vulnerability of 4.2.2 above, this makes it possible for an attacker to escalate privileges
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Diaenergie | <1.8.02.004 | |
Delta Electronics DIAEnergie | <1.9 | 1.9 |
Delta Electronics has fixed the reported vulnerabilities in Version 1.08.02.004. Users should contact Delta customer service or a Delta representative for this release, as it will not be released publicly. Delta is working on a public release that will include these fixes and other features on June 30, 2022.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Delta Electronics DIAEnergie is CVE-2022-1098.
The severity level of CVE-2022-1098 is high with a score of 7.8.
An attacker can exploit CVE-2022-1098 by leveraging a DLL hijacking condition combined with the Incorrect Default Permissions vulnerability to escalate privileges.
All versions of Delta Electronics DIAEnergie prior to 1.8.02.004 are affected by CVE-2022-1098.
To fix CVE-2022-1098 in Delta Electronics DIAEnergie, it is recommended to update to version 1.8.02.004 or later.