Impact
Improper Access Control in DIAEnergie allows an attacker to gain unauthorized access to system functionality or sensitive information that should be protected by authentication or authorization controls. The vulnerability could enable users to perform operations or view data beyond their intended privileges, potentially compromising confidentiality or integrity of the application’s data.
Affected Systems
Deltaww’s DIAEnergie software, versions prior to 1.11.00.022, is affected. The vulnerability impacts any deployment of this product that has not been upgraded to the specified version or later.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS is not available, so the exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the vulnerability arises from improper access control and would likely be exploitable by an attacker who can interact with the application—either locally or remotely if that interface is exposed. No specific exploit code or configuration is mentioned, so the attack would require reaching the affected component and manipulating authentication or authorization controls.
OpenCVE Enrichment