Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-21-238-03 | Mitigation Patch Third Party Advisory US Government Resource |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: icscert
Published: 2022-03-22T00:00:00
Updated: 2022-03-25T18:02:30
Reserved: 2022-03-15T00:00:00
Link: CVE-2022-0988
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-03-25T19:15:10.460
Modified: 2022-04-01T12:24:18.417
Link: CVE-2022-0988
JSON object: View
Redhat Information
No data.
CWE