VYPR
Unrated severityNVD Advisory· Published Mar 29, 2022· Updated Apr 16, 2025

Delta Electronics DIAEnergie Incorrect Default Permissions

CVE-2022-26839

Description

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Delta Electronics DIAEnergie versions prior to 1.9 have incorrect default permissions, allowing low-privileged attackers to plant malicious DLLs or replace executables.

Vulnerability

Delta Electronics DIAEnergie versions prior to 1.9 suffer from an incorrect default permission vulnerability (CWE-276). The application's filesystem permissions are overly permissive by default, enabling a local attacker to plant new files (such as DLLs) or overwrite existing executable files. The affected product is used for industrial energy management.

Exploitation

An attacker needs local access to the system with low privileges (CVSSv3 AV:L/PR:L). No user interaction is required. The attacker can write arbitrary files into directories where DIAEnergie loads executables or libraries. By placing a malicious DLL in a search path that the application uses, the attacker can cause the application to load the attacker's code instead of the legitimate library.

Impact

Successful exploitation allows the attacker to achieve code execution in the context of the DIAEnergie application, which often runs with elevated privileges. The impact includes high confidentiality, integrity, and availability impact, potentially leading to full system compromise [1].

Mitigation

Delta Electronics has released DIAEnergie version 1.9, which fixes this vulnerability [1]. Users should upgrade to version 1.9 or later. If immediate upgrade is not possible, limit local access to trusted users and monitor file changes in the installation directory. No known public KEV listing exists.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.