Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-21-238-03 | Mitigation Patch Third Party Advisory US Government Resource |
https://www.cisa.gov/uscert/ics/advisories/icsa-21-238-03 | Mitigation Patch Third Party Advisory US Government Resource |
Configurations
History
21 Nov 2024, 06:39
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 7.1 |
References | () https://www.cisa.gov/uscert/ics/advisories/icsa-21-238-03 - Mitigation, Patch, Third Party Advisory, US Government Resource |
Information
Published : 2022-03-25 19:15
Updated : 2024-11-21 06:39
NVD link : CVE-2022-0988
Mitre link : CVE-2022-0988
CVE.ORG link : CVE-2022-0988
JSON object : View
Products Affected
deltaww
- diaenergie
CWE
CWE-319
Cleartext Transmission of Sensitive Information