Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Delta recommends users update to DIAEnergie v1.10.00.005. Users can request this version of DIAEnergie from Delta Electronics' regional sales or agents https://www.deltaww.com/en/customerService .
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-25202 | Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality. |
Thu, 17 Oct 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 |
Thu, 17 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:deltaww:diaenergie:-:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Thu, 17 Oct 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality. | Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality. |
| Title | Delta Electronics DIAEnergie Improper Authorization | Client-Side Enforcement of Server-Side Security in Delta Electronics DIAEnergie |
| Weaknesses | CWE-602 |
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-10-17T18:45:56.861Z
Reserved: 2024-03-12T15:07:02.648Z
Link: CVE-2024-28029
Updated: 2024-08-02T00:48:47.726Z
Status : Modified
Published: 2024-03-21T22:15:11.353
Modified: 2024-11-21T09:05:40.260
Link: CVE-2024-28029
No data.
OpenCVE Enrichment
No data.
EUVD