Impact
The vulnerability is a path traversal flaw that allows an attacker to reference filesystem paths outside the intended directory boundaries. This could enable reading of arbitrary files, potentially exposing sensitive information, and if writable locations are reachable, could lead to arbitrary file write or code execution in the context of the application.
Affected Systems
The affected product is Delta's DIAEnergie, with vulnerability present in all releases prior to version 1.11.00.022.
Risk and Exploitability
The CVSS score of 9.1 indicates high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, but the high score and the nature of the flaw suggest that exploitation is likely feasible over a remote network connection, such as through the web interface or API. An attacker with network access could craft requests containing malicious path sequences to read arbitrary files or, if write access is possible, modify files to achieve further compromise.
OpenCVE Enrichment