CVE-2022-25347
9.8
CRITICAL · CVSS 3.1 · EPSS 11.4% (pctl 96)
Patch early
EPSS 11.4% — above the 10% action threshold.
Description
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 11.39% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-37 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-03-29 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| deltaww | diaenergie |
References
→ the Explorer · watch your stack · NVD