CVE-2023-0822: Improper Authorization
Published Feb 17, 2023
·Updated
The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass authorization and access privileged functionality.
Affected Software
3 affected components
Delta Electronics DIAEnergie versions prior to v1.9.01.002
Delta Electronics DIAEnergie versions prior to v1.9.02.001
Deltaww Diaenergie<1.9.03.001
Remediation
Information
Delta did not publicly release v1.9.01.002, v1.9.02.001, and v1.9.03.001, which address these vulnerabilities. Users are encouraged to contact Delta to receive these updates.
Event History
Feb 17, 2023
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-0822.
2
What is the severity level of CVE-2023-0822?
The severity level of CVE-2023-0822 is high (8.8).
3
Which product is affected by CVE-2023-0822?
The affected product is DIAEnergie (versions prior to v1.9.03.001) by Deltaww.
4
What is the impact of CVE-2023-0822?
CVE-2023-0822 allows an unauthorized user to bypass authorization and access privileged functionality.
5
Is there a fix available for CVE-2023-0822?
Yes, upgrading to version 1.9.03.001 of DIAEnergie resolves the vulnerability.