CVE-2022-40965: Delta Electronics DIAEnergie
Published Oct 27, 2022
·Updated
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API.
Affected Software
3 affected components
Delta Electronics DIAEnergie versions prior to v1.9.01.002
Delta Electronics DIAEnergie versions prior to v1.9.02.001
Deltaww Diaenergie<1.9.01.002
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta Electronics DIAEnergieto a version that resolves this vulnerability.Fixed in v1.9.01.002
Event History
Oct 27, 2022
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-40965?
CVE-2022-40965 is a stored cross-site scripting vulnerability in the DIAEnergie product prior to version 1.9.01.002.
2
How severe is CVE-2022-40965?
CVE-2022-40965 is considered high severity with a CVSS score of 5.4.
3
What is the affected product of CVE-2022-40965?
The affected product of CVE-2022-40965 is DIAEnergie prior to version 1.9.01.002.
4
How does CVE-2022-40965 affect the DIAEnergie?
CVE-2022-40965 enables stored cross-site scripting attacks through the PostEnergyType API in DIAEnergie.
5
How can I fix CVE-2022-40965?
To fix CVE-2022-40965, update DIAEnergie to version 1.9.01.002 or newer.