CVE-2022-27175: Delta Electronics DIAEnergie SQL Injection in GetCalcTagList
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetCalcTagList. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-27175.
What is the affected software?
The affected software is Delta Electronics DIAEnergie, all versions prior to 1.8.02.004.
What is the severity of CVE-2022-27175?
The severity of CVE-2022-27175 is critical, with a CVSS score of 9.8.
What is the specific vulnerability in GetCalcTagList?
The specific vulnerability is a blind SQL injection vulnerability.
What can an attacker do with this vulnerability?
An attacker can inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
How can I fix this vulnerability?
To fix this vulnerability, update Delta Electronics DIAEnergie to version 1.8.02.004 or later.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at the following reference: https://www.cisa.gov/uscert/ics/advisories/icsa-22-081-01