CVE-2022-26887: Delta Electronics DIAEnergie SQL Injection in DIAE_HandlerTag_KID.ashx
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAEloopmapHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-26887?
CVE-2022-26887 is a blind SQL injection vulnerability in Delta Electronics DIAEnergie, allowing an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
What is the severity of CVE-2022-26887?
CVE-2022-26887 has a severity rating of 9.8, which is classified as critical.
How can an attacker exploit CVE-2022-26887?
An attacker can exploit CVE-2022-26887 by injecting arbitrary SQL queries through the DIAE_loopmapHandler.ashx component, allowing them to retrieve and modify database contents and execute system commands.
Which versions of Delta Electronics DIAEnergie are affected by CVE-2022-26887?
All versions of Delta Electronics DIAEnergie prior to 1.8.02.004 are affected by CVE-2022-26887.
Is there a fix available for CVE-2022-26887?
Yes, upgrading to version 1.8.02.004 of Delta Electronics DIAEnergie will fix the CVE-2022-26887 vulnerability.