CVE-2022-1098

HIGH

Deltaww Diaenergie < 1.8.02.004 - Uncontrolled Search Path

Title source: rule

Description

Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default Permissions vulnerability of 4.2.2 above, this makes it possible for an attacker to escalate privileges

Scores

CVSS v3 7.8
EPSS 0.0004
EPSS Percentile 13.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (1)

deltaww/diaenergie < 1.8.02.004

Timeline

Published Apr 01, 2022
Tracked Since Feb 18, 2026