CVE-2021-31558: Delta Electronics DIAEnergie (Update A)
Published Dec 22, 2021
·Updated
DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAEhierarchyHandler.ashx”.
Affected Software
2 affected componentsFixes available
Delta Electronics DIAEnergie<1.9
1.9
Deltaww Diaenergie<=1.7.5
Remediation
Information
Delta Electronics has released an updated version of DIAEnergie and recommends users install v1.8.0 and later on all affected systems.
Event History
Dec 22, 2021
CVE Published
via MITRE·06:06 PM
Data Sourced
via MITRE·06:06 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-31558.
2
What is the severity of CVE-2021-31558?
The severity of CVE-2021-31558 is medium with a severity value of 6.1.
3
Which software versions are affected by CVE-2021-31558?
DIAEnergie Version 1.7.5 and prior.
4
How can an attacker exploit CVE-2021-31558?
An attacker can exploit CVE-2021-31558 by injecting arbitrary code into the 'descr' parameter of the script 'DIAE_hierarchyHandler.ashx' as an unauthenticated user, leading to stored cross-site scripting.
5
Are there any references for CVE-2021-31558?
Yes, you can find more information about CVE-2021-31558 at the following reference: [link](https://www.cisa.gov/uscert/ics/advisories/icsa-21-238-03)