Authentication Bypass Vulnerability in Delta Electronics DIAEnergie
CVE-2021-32967

9.8CRITICAL

Key Information:

Vendor

Deltaww

Vendor
CVE Published:
30 August 2021

What is CVE-2021-32967?

A security flaw in Delta Electronics DIAEnergie versions prior to 1.7.5 enables an unauthorized user to create a new administrative account on the device. This flaw can potentially give attackers the ability to login with full administrative privileges, compromising the security and integrity of the device. Proper patching and updates are crucial to mitigate this risk.

Affected Version(s)

Delta Electronics DIAEnergie DIAEnergie Version 1.7.5 and prior

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.