Advisories

Delta Electronics DIAEnergie Authentication Bypass via Web API Query String

Go Back
severity
critical
date
Affecting
  • DIAEnergie < 1.11.00.022

CWE
  • CWE-288 Authentication Bypass Using an Alternate Path or Channel
CVSS
9.3
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
Alex Williams from Pellera Technologies
Description
Delta Electronics DIAEnergie before 1.11.00.022 contains an authentication bypass vulnerability in its global Web API filters that allows remote unauthenticated attackers to bypass JWT and basic authentication checks by appending a whitelisted pattern to the query string of any protected endpoint. Attackers can exploit the unanchored whitelist matching against the full request URI, including attacker-controlled query parameters, to invoke privileged API actions such as creating administrator accounts and taking over the application.

Ready to get Started?

Explore VulnCheck, a next-generation Cyber Threat Intelligence platform, which provides exploit and vulnerability intelligence to help you prioritize and remediate vulnerabilities that matter.
  • Vulnerability Prioritization
    Prioritize vulnerabilities that matter based on the threat landscape and defer vulnerabilities that don't.
  • Early Warning System
    Real-time alerting of changes in the vulnerability landscape so that you can take action before the attacks start.