CVE-2021-44471: Delta Electronics DIAEnergie (Update A)
DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “name” of the script “DIAEHandlerAlarmGroup.ashx”.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-44471?
CVE-2021-44471 is a vulnerability in DIAEnergie version 1.7.5 and prior, which allows an unauthenticated user to inject arbitrary code into the 'name' parameter of the 'DIAE_HandlerAlarmGroup.ashx' script, leading to stored cross-site scripting (XSS).
What is the severity of CVE-2021-44471?
The severity of CVE-2021-44471 is high, with a CVSS severity score of 6.1.
How does CVE-2021-44471 affect DIAEnergie?
CVE-2021-44471 affects DIAEnergie version 1.7.5 and prior by allowing an unauthenticated user to inject arbitrary code into the 'name' parameter of the 'DIAE_HandlerAlarmGroup.ashx' script, which can lead to stored cross-site scripting (XSS) attacks.
How can I fix CVE-2021-44471?
To fix CVE-2021-44471, it is recommended to update DIAEnergie to a version that is not affected by this vulnerability.
Where can I find more information about CVE-2021-44471?
You can find more information about CVE-2021-44471 at the following reference: https://www.cisa.gov/uscert/ics/advisories/icsa-21-238-03