CVE-2022-26667: Delta Electronics DIAEnergie SQL Injection in GetDemandAnalysisData
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetDemandAnalysisData. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26667?
The severity of CVE-2022-26667 is critical (9.8 out of 10).
How does the blind SQL injection vulnerability in Delta Electronics DIAEnergie (prior to version 1.8.02.004) work?
The blind SQL injection vulnerability allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
What is the affected software for CVE-2022-26667?
The affected software for CVE-2022-26667 is Delta Electronics DIAEnergie versions prior to 1.8.02.004.
How can an attacker exploit the blind SQL injection vulnerability in Delta Electronics DIAEnergie?
Attackers can exploit the blind SQL injection vulnerability in Delta Electronics DIAEnergie by injecting malicious SQL queries that target the GetDemandAnalysisData function.
Is there a fix available for CVE-2022-26667?
Yes, updating to version 1.8.02.004 of Delta Electronics DIAEnergie will fix the blind SQL injection vulnerability.