Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-25202 Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.
Fixes

Solution

Delta recommends users update to DIAEnergie v1.10.00.005. Users can request this version of DIAEnergie from Delta Electronics' regional sales or agents https://www.deltaww.com/en/customerService .


Workaround

No workaround given by the vendor.

History

Thu, 17 Oct 2024 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 17 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:deltaww:diaenergie:-:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Oct 2024 19:00:00 +0000

Type Values Removed Values Added
Description Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality. Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.
Title Delta Electronics DIAEnergie Improper Authorization Client-Side Enforcement of Server-Side Security in Delta Electronics DIAEnergie
Weaknesses CWE-602

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-10-17T18:45:56.861Z

Reserved: 2024-03-12T15:07:02.648Z

Link: CVE-2024-28029

cve-icon Vulnrichment

Updated: 2024-08-02T00:48:47.726Z

cve-icon NVD

Status : Modified

Published: 2024-03-21T22:15:11.353

Modified: 2024-11-21T09:05:40.260

Link: CVE-2024-28029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.