CVE-2022-41651: Delta Electronics DIAEnergie
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the SetPF API.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta Electronics DIAEnergieto a version that resolves this vulnerability.Fixed in 1.9.01.002
Event History
Frequently Asked Questions
What is CVE-2022-41651?
CVE-2022-41651 is a stored cross-site scripting vulnerability in the DIAEnergie product prior to v1.9.01.002.
What is the severity of CVE-2022-41651?
CVE-2022-41651 has a severity rating of 5.4 (high).
How does CVE-2022-41651 affect the DIAEnergie product?
CVE-2022-41651 affects DIAEnergie versions prior to v1.9.01.002, allowing for stored cross-site scripting attacks through the SetPF API.
How can I mitigate CVE-2022-41651?
To mitigate CVE-2022-41651, it is recommended to update the DIAEnergie product to version v1.9.01.002 or later.
Where can I find more information about CVE-2022-41651?
More information about CVE-2022-41651 can be found at the following reference: https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-06