CVE-2022-41555: Delta Electronics DIAEnergie
Published Oct 27, 2022
·Updated
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API.
Affected Software
3 affected components
Delta Electronics DIAEnergie versions prior to v1.9.01.002
Delta Electronics DIAEnergie versions prior to v1.9.02.001
Deltaww Diaenergie<1.9.01.002
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta Electronics DIAEnergieto a version that resolves this vulnerability.Fixed in v1.9.01.002
Event History
Oct 27, 2022
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-41555.
2
What is the severity of CVE-2022-41555?
The severity of CVE-2022-41555 is high with a CVSS score of 5.4.
3
What is the affected product and its version?
The affected product is DIAEnergie and the vulnerable versions are prior to v1.9.01.002.
4
What type of vulnerability is CVE-2022-41555?
CVE-2022-41555 is a stored cross-site scripting vulnerability.
5
Is there a fix available for CVE-2022-41555?
Yes, upgrading to version v1.9.01.002 or later of DIAEnergie fixes the vulnerability.