CVE-2022-1375: SQL Injection
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAEslogHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2022-1375.
What is the severity of CVE-2022-1375?
The severity of CVE-2022-1375 is critical with a score of 9.8.
What is the affected software for CVE-2022-1375?
The affected software for CVE-2022-1375 is Delta Electronics DIAEnergie versions prior to 1.8.02.004.
What is the description of CVE-2022-1375?
CVE-2022-1375 is a blind SQL injection vulnerability in Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) that allows attackers to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Is there a fix available for CVE-2022-1375?
Yes, a fix is available for CVE-2022-1375. It is recommended to update to version 1.8.02.004 or later of Delta Electronics DIAEnergie.