CVE-2024-28029: Client-Side Enforcement of Server-Side Security in Delta Electronics DIAEnergie
Published Mar 21, 2024
·Updated
Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.
Affected Software
1 affected component
Deltaww Diaenergie<1.10.00.005
Remediation
Information
Delta recommends users update to DIAEnergie v1.10.00.005. Users can request this version of DIAEnergie from Delta Electronics' regional sales or agents https://www.deltaww.com/en/customerService .
Event History
Mar 21, 2024
CVE Published
via MITRE·10:04 PM
Data Sourced
via MITRE·10:04 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28029?
CVE-2024-28029 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-28029?
To fix CVE-2024-28029, ensure that server-side privilege verification is implemented correctly.
3
Who is affected by CVE-2024-28029?
CVE-2024-28029 affects users of the DIAEnergie software versions prior to 1.10.00.005.
4
What impact does CVE-2024-28029 have on users?
CVE-2024-28029 allows users with limited privileges to bypass authorization and access restricted functionality.
5
Is there a patch available for CVE-2024-28029?
Yes, users should upgrade to the latest version of DIAEnergie to address CVE-2024-28029.