The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass authorization and access privileged functionality.
Solution:
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-06 | third party advisory us government resource |