First published: Thu Dec 16 2021(Updated: )
DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are returned by “.NET Request.QueryString”.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Diaenergie | <=1.7.5 | |
Delta Electronics DIAEnergie | <1.9 | 1.9 |
Delta Electronics has released an updated version of DIAEnergie and recommends users install v1.8.0 and later on all affected systems.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23228 is a vulnerability in DIAEnergie version 1.7.5 and prior that allows for a reflected cross-site scripting attack through error pages returned by '.NET Request.QueryString'.
CVE-2021-23228 has a severity rating of 6.1 (high).
DIAEnergie version 1.7.5 and prior are affected by CVE-2021-23228.
To fix CVE-2021-23228, it is recommended to upgrade to a version of DIAEnergie that is not affected by the vulnerability.
More information about CVE-2021-23228 can be found at the following link: [https://www.cisa.gov/uscert/ics/advisories/icsa-21-238-03]