CVE-2022-1378: SQL Injection
Published May 2, 2022
·Updated
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAEpgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Affected Software
2 affected componentsFixes available
Delta Electronics DIAEnergie<1.9
1.9
Deltaww Diaenergie<1.8.02.004
Remediation
Information
Delta Electronics has fixed the reported vulnerabilities in Version 1.08.02.004. Users should contact Delta customer service or a Delta representative for this release, as it will not be released publicly. Delta is working on a public release that will include these fixes and other features on June 30, 2022.
Event History
May 2, 2022
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2022-1378.
2
What is the severity of CVE-2022-1378?
The severity of CVE-2022-1378 is critical with a score of 9.8.
3
Which software versions are affected by CVE-2022-1378?
All versions prior to 1.8.02.004 of Delta Electronics DIAEnergie are affected by CVE-2022-1378.
4
What is the impact of CVE-2022-1378?
CVE-2022-1378 allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
5
Is there a fix available for CVE-2022-1378?
Yes, updating to version 1.8.02.004 of Delta Electronics DIAEnergie will fix CVE-2022-1378.