CVE-2021-38390: SQL Injection
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DIAEnergieto a version that resolves this vulnerability.Fixed in 1.9 - Upgrade
Upgrade
Delta Electronics DIAEnergieto a version that resolves this vulnerability.Fixed in 1.7.5
Event History
Frequently Asked Questions
What is CVE-2021-38390?
CVE-2021-38390 is a Blind SQL injection vulnerability in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior.
How severe is CVE-2021-38390?
CVE-2021-38390 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2021-38390?
Delta Electronics DIAEnergie Version 1.7.5 and prior are affected by CVE-2021-38390.
How does CVE-2021-38390 exploit work?
CVE-2021-38390 exploits a Blind SQL injection vulnerability by supplying a user-controlled value through the parameter egyid that is used in an SQL query without proper validation.
Is there a patch available for CVE-2021-38390?
I could not find information on a specific patch for CVE-2021-38390. It is recommended to contact the vendor for further information and updates.