Delta Electronics DIAEnergie CLEARTEXT Transmission of Sensitive Information
Description
Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Delta DIAEnergie versions prior to 1.9 transmit data in cleartext over HTTP, allowing remote attackers to intercept sensitive information.
Vulnerability
Delta Electronics DIAEnergie, versions prior to 1.9, runs its web application by default on HTTP, transmitting data in cleartext. This cleartext transmission vulnerability (CWE-319) affects version 1.7.5 and earlier, as noted in the advisory [1]. The affected product does not enforce HTTPS by default, exposing all communication between the client and the device.
Exploitation
An attacker with network access to the traffic between a client and the DIAEnergie web interface can passively capture unencrypted HTTP sessions. No authentication or user interaction is required; the attacker only needs to be positioned to observe the network traffic (e.g., on the same local network or via a compromised intermediary). The attacker can then read the transmitted data, including credentials and other sensitive information.
Impact
Successful exploitation allows an attacker to remotely read transmitted information between the client and product, leading to disclosure of sensitive data such as passwords, session tokens, and operational details. While the advisory lists this vulnerability with a CVSS v3 base score of 9.8, the specific cleartext transmission issue contributes to the overall risk of information disclosure.
Mitigation
Delta has released DIAEnergie version 1.9, which addresses this vulnerability. Users should update to version 1.9 or later. If immediate upgrade is not possible, mitigating measures include enforcing HTTPS at the network level (e.g., using a reverse proxy or VPN) and restricting network access to the DIAEnergie interface to trusted hosts only.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=1.7.5+ 1 more
- (no CPE)range: <=1.7.5
- (no CPE)range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.cisa.gov/uscert/ics/advisories/icsa-21-238-03mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.