Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-21-238-03 | Mitigation Patch Third Party Advisory US Government Resource |
Configurations
Information
Published : 2022-03-25 12:15
Updated : 2022-04-01 05:24
NVD link : CVE-2022-0988
Mitre link : CVE-2022-0988
JSON object : View
CWE
CWE-319
Cleartext Transmission of Sensitive Information
Products Affected
deltaww
- diaenergie