CVE-2021-38391: SQL Injection
A Blind SQL injection vulnerability exists in the /DataHandler/AM/AMHandler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DIAEnergieto a version that resolves this vulnerability.Fixed in 1.9
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38391?
CVE-2021-38391 has been classified as a high severity vulnerability due to its potential for a Blind SQL injection attack.
How do I fix CVE-2021-38391?
To fix CVE-2021-38391, upgrade the Delta Electronics DIAEnergie software to version 1.9 or later.
What versions of DIAEnergie are affected by CVE-2021-38391?
CVE-2021-38391 affects Delta Electronics DIAEnergie versions 1.7.5 and earlier.
Can CVE-2021-38391 lead to data exposure?
Yes, CVE-2021-38391 can allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized data exposure.
Is authentication required to exploit CVE-2021-38391?
Exploitation of CVE-2021-38391 does not require authentication, making it more critical.