Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-21-238-03 Mitigation Patch Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2022-03-22T00:00:00

Updated: 2022-03-25T18:02:30

Reserved: 2022-03-15T00:00:00


Link: CVE-2022-0988

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-03-25T19:15:10.460

Modified: 2022-04-01T12:24:18.417


Link: CVE-2022-0988

JSON object: View

cve-icon Redhat Information

No data.

CWE