CVE-2022-41133: Delta Electronics DIAEnergie
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAElinemessagesettingsListParameters. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta Electronics DIAEnergieto a version that resolves this vulnerability.Fixed in v1.9.01.002 - Compensating control
Limit exposure of DIAEnergie endpoints to prevent exploitation of the SQL injection in GetDIAE_line_message_settingsListParameters by restricting access to authenticated/authorized users only.
Event History
Frequently Asked Questions
What is vulnerability CVE-2022-41133?
Vulnerability CVE-2022-41133 is a SQL injection vulnerability in the DIAEnergie product (versions prior to v1.9.01.002) that exists in the GetDIAE_line_message_settingsListParameters function.
How severe is vulnerability CVE-2022-41133?
Vulnerability CVE-2022-41133 has a severity score of 8.8 (high).
Who is affected by vulnerability CVE-2022-41133?
Users of DIAEnergie versions prior to v1.9.01.002 are affected by vulnerability CVE-2022-41133.
How can an attacker exploit vulnerability CVE-2022-41133?
An authenticated attacker with low privileges can exploit vulnerability CVE-2022-41133 by injecting arbitrary SQL queries.
Is there a fix available for vulnerability CVE-2022-41133?
A fix is available in version v1.9.01.002 of the DIAEnergie product. Users should upgrade to this version to mitigate the vulnerability.