CVE-2022-40967: Delta Electronics DIAEnergie
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoTHubNameExisted. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta Electronics DIAEnergieto a version that resolves this vulnerability.Fixed in v1.9.01.002Patch CheckIoTHubNameExisted
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-40967.
What is the severity of CVE-2022-40967?
The severity of CVE-2022-40967 is high with a CVSS score of 8.8.
Which product and versions are affected by CVE-2022-40967?
The affected product is DIAEnergie, versions prior to v1.9.01.002.
What is the impact of CVE-2022-40967?
A low-privileged authenticated attacker could exploit the SQL injection vulnerability to inject arbitrary SQL queries.
Is there a fix available for CVE-2022-40967?
Yes, upgrading to version v1.9.01.002 of DIAEnergie will fix the SQL injection vulnerability.