CVE-2022-26839
Summary
| CVE | CVE-2022-26839 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-29 17:15:00 UTC |
| Updated | 2022-04-04 19:29:00 UTC |
| Description | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files. |
Risk And Classification
Problem Types: CWE-276
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Deltaww | Diaenergie | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Delta Electronics DIAEnergie (Update B) | CISA | CONFIRM | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Michael Heinzl and Dusan Stevanovic of Trend Micro’s Zero Day Initiative reported these vulnerabilities to CISA.
Legacy QID Mappings
- 591001 Delta Electronics DIAEnergie (Update C) Multiple Vulnerabilities (ICSA-22-081-01)