First published: Wed Dec 22 2021(Updated: )
DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is injected into the parameter “name” of the script “HandlerEnergyType.ashx”.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Diaenergie | <=1.7.5 | |
Delta Electronics DIAEnergie | <1.9 | 1.9 |
<=1.7.5 |
Delta Electronics has released an updated version of DIAEnergie and recommends users install v1.8.0 and later on all affected systems.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the DIAEnergie vulnerability is CVE-2021-44544.
The affected software for the DIAEnergie vulnerability is DIAEnergie Version 1.7.5 and prior.
The severity level of the DIAEnergie vulnerability is high with a value of 6.1.
The DIAEnergie vulnerability occurs when arbitrary code is injected into the parameter 'name' of the script 'HandlerEnergyType.ashx', resulting in multiple cross-site scripting vulnerabilities.
Yes, you can find more information about the DIAEnergie vulnerability at the following reference: https://www.cisa.gov/uscert/ics/advisories/icsa-21-238-03