CVE-2022-41701: Delta Electronics DIAEnergie
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutShift API.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta Electronics DIAEnergieto a version that resolves this vulnerability.Fixed in v1.9.01.002 - Compensating control
Until DIAEnergie is updated to v1.9.01.002, mitigate stored XSS exposure via the PutShift API by restricting access to the PutShift API to trusted users/systems (e.g., via network/firewall controls or application access controls) to reduce the ability to trigger the vulnerable endpoint.
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2022-41701.
What is the severity of CVE-2022-41701?
The severity of CVE-2022-41701 is high with a severity value of 5.4.
What is the affected product of CVE-2022-41701?
The affected product of CVE-2022-41701 is DIAEnergie (versions prior to v1.9.01.002).
What is the type of vulnerability of CVE-2022-41701?
CVE-2022-41701 is a stored cross-site scripting vulnerability.
How can I fix CVE-2022-41701?
To fix CVE-2022-41701, update the affected product DIAEnergie to version v1.9.01.002 or later.