"value":"\nDelta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.\n\n"
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
"value":"\n\n<span style=\"background-color: rgb(255, 255, 255);\">Delta Electronics recommends users update to DIAEnergie v1.10.01.004 to mitigate these vulnerabilities. Users can request this version of DIAEnergie from Delta Electronics' regional sales or agents.</span>\n\n<br>"
}
],
"value":"\nDelta Electronics recommends users update to DIAEnergie v1.10.01.004 to mitigate these vulnerabilities. Users can request this version of DIAEnergie from Delta Electronics' regional sales or agents.\n\n"
}
],
"credits":[
{
"lang":"en",
"value":"Michael Heinzl reported these vulnerabilities to CISA."