First published: Fri Feb 17 2023(Updated: )
The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass authorization and access privileged functionality.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Diaenergie | <1.9.03.001 | |
Delta Electronics DIAEnergie versions prior to v1.9.01.002 | ||
Delta Electronics DIAEnergie versions prior to v1.9.02.001 |
Delta did not publicly release v1.9.01.002, v1.9.02.001, and v1.9.03.001, which address these vulnerabilities. Users are encouraged to contact Delta to receive these updates.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-0822.
The severity level of CVE-2023-0822 is high (8.8).
The affected product is DIAEnergie (versions prior to v1.9.03.001) by Deltaww.
CVE-2023-0822 allows an unauthorized user to bypass authorization and access privileged functionality.
Yes, upgrading to version 1.9.03.001 of DIAEnergie resolves the vulnerability.