CVE-2021-32983: SQL Injection
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerCFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32983?
CVE-2021-32983 is classified as a significant security risk due to its potential for remote exploitation via SQL injection.
How do I fix CVE-2021-32983?
To mitigate CVE-2021-32983, upgrade to DIAEnergie version 1.9 or later, which addresses this vulnerability.
What applications are affected by CVE-2021-32983?
CVE-2021-32983 affects Delta Electronics DIAEnergie versions 1.7.5 and prior.
What type of attack is possible with CVE-2021-32983?
CVE-2021-32983 allows an attacker to perform a blind SQL injection, potentially leading to unauthorized data access.
Is CVE-2021-32983 actively being exploited?
While there have been no public reports of active exploitation, the nature of blind SQL injection vulnerabilities makes them a serious concern.