CVE-2022-1372: SQL Injection
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1372?
The severity of CVE-2022-1372 is critical with a CVSS score of 9.8.
What is the affected software for CVE-2022-1372?
The affected software for CVE-2022-1372 is Delta Electronics DIAEnergie version up to 1.8.02.004.
How can an attacker exploit CVE-2022-1372?
An attacker can exploit CVE-2022-1372 by injecting arbitrary SQL queries into the dlSlog.aspx page, allowing them to retrieve and modify database contents and execute system commands.
Is there a fix available for CVE-2022-1372?
Yes, Delta Electronics has released a fix for CVE-2022-1372 in version 1.8.02.004 of DIAEnergie.
Where can I find more information about CVE-2022-1372?
You can find more information about CVE-2022-1372 on the official US-CERT Advisory ICSA-22-081-01.