Impact
The vulnerability lets an attacker supply a user‑controlled key and bypass the application’s authorization checks. If exploited, the attacker can gain unauthorized access to protected functions or data. The flaw is a direct example of CWE‑639 (Authorization Bypass Through User‑Controlled Key).
Affected Systems
Affected are all installations of Deltaww’s DIAEnergie product running a version prior to 1.11.00.022. No other product or version is listed as impacted in the advisory.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score is not available, suggesting no publicly known exploitation activity. The vulnerability is not included in the CISA KEV catalog. Attackers would need to supply the specific key value, so the required attack vector is inferred to be either local or remote access to the application, provided the user‑controlled key mechanism is exposed. Without a public exploit, the likelihood of exploitation remains low but non‑zero.
OpenCVE Enrichment