CVE-2024-34033: Deltaww Diaenergie

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.

Affected products

  • Deltaww Diaenergie: version 1.10.00.005 only

Published 2024-05-03. Last modified 2026-06-17.