CVE-2022-26349: Delta Electronics DIAEnergie SQL Injection in DIAE_eccoefficientHandler.ashx
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAEeccoefficientHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-26349.
What is the severity of CVE-2022-26349?
The severity of CVE-2022-26349 is critical, with a severity value of 9.8.
What is the affected software for CVE-2022-26349?
The affected software for CVE-2022-26349 is Delta Electronics DIAEnergie versions prior to 1.8.02.004.
What is the vulnerability description for CVE-2022-26349?
CVE-2022-26349 is a blind SQL injection vulnerability in Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) that exists in DIAE_eccoefficientHandler.ashx, allowing an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Is there any fix available for CVE-2022-26349?
Yes, updating to version 1.8.02.004 or later of Delta Electronics DIAEnergie will fix the vulnerability.