Impact
Improper authentication in DIAEnergie allows an attacker to bypass the login process, potentially granting unauthorized access to the application and its data. The flaw is identified as CWE-287. Users operating versions prior to 1.11.00.022 are susceptible, and exploitation could provide full control over the interface and any protected resources.
Affected Systems
The vulnerability affects the Deltaww product DIAEnergie. Any installation of DIAEnergie before version 1.11.00.022 is vulnerable, as indicated by the vendor’s CPE designation for deltaww:diaenergie.
Risk and Exploitability
With a CVSS score of 9.8, this issue is critical. While the EPSS score is not available, the remote nature of authentication bypass suggests a high likelihood of exploitation, especially if the service is exposed to the internet or an internal network. The vulnerability is not listed in CISA KEV, but that does not mitigate the severity. The likely attack vector is a remote attacker accessing the DIAEnergie interface over the network and using the bypass to gain privileged access.
OpenCVE Enrichment