CVE-2022-1377: SQL Injection
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAErltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1377?
The severity of CVE-2022-1377 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2022-1377?
All versions of Delta Electronics DIAEnergie prior to 1.8.02.004 are affected by CVE-2022-1377.
What is the vulnerability in Delta Electronics DIAEnergie?
The vulnerability in Delta Electronics DIAEnergie is a blind SQL injection vulnerability in DIAE_rltHandler.ashx.
What can an attacker do with CVE-2022-1377?
An attacker can inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
How can I mitigate CVE-2022-1377?
To mitigate CVE-2022-1377, it is recommended to update Delta Electronics DIAEnergie to version 1.8.02.004 or later.