First published: Mon May 02 2022(Updated: )
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Diaenergie | <1.8.02.004 | |
Delta Electronics DIAEnergie | <1.9 | 1.9 |
Delta Electronics has fixed the reported vulnerabilities in Version 1.08.02.004. Users should contact Delta customer service or a Delta representative for this release, as it will not be released publicly. Delta is working on a public release that will include these fixes and other features on June 30, 2022.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-1374 is critical with a CVSS score of 9.8.
The affected software for CVE-2022-1374 is Delta Electronics DIAEnergie version 1.8.02.004 and earlier.
CVE-2022-1374 is a blind SQL injection vulnerability in DIAE_unHandler.ashx in Delta Electronics DIAEnergie.
An attacker can exploit CVE-2022-1374 to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Yes, upgrading to Delta Electronics DIAEnergie version 1.8.02.004 or later will fix CVE-2022-1374.