Delta Electronics DIAEnergie Incorrect Default Permissions
Description
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Delta Electronics DIAEnergie versions prior to 1.9 have incorrect default permissions, allowing low-privileged attackers to plant malicious DLLs or replace executables.
Vulnerability
Delta Electronics DIAEnergie versions prior to 1.9 suffer from an incorrect default permission vulnerability (CWE-276). The application's filesystem permissions are overly permissive by default, enabling a local attacker to plant new files (such as DLLs) or overwrite existing executable files. The affected product is used for industrial energy management.
Exploitation
An attacker needs local access to the system with low privileges (CVSSv3 AV:L/PR:L). No user interaction is required. The attacker can write arbitrary files into directories where DIAEnergie loads executables or libraries. By placing a malicious DLL in a search path that the application uses, the attacker can cause the application to load the attacker's code instead of the legitimate library.
Impact
Successful exploitation allows the attacker to achieve code execution in the context of the DIAEnergie application, which often runs with elevated privileges. The impact includes high confidentiality, integrity, and availability impact, potentially leading to full system compromise [1].
Mitigation
Delta Electronics has released DIAEnergie version 1.9, which fixes this vulnerability [1]. Users should upgrade to version 1.9 or later. If immediate upgrade is not possible, limit local access to trusted users and monitor file changes in the installation directory. No known public KEV listing exists.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<1.8.02.004+ 1 more
- (no CPE)range: <1.8.02.004
- (no CPE)range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.cisa.gov/uscert/ics/advisories/icsa-22-081-01mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.