CVE-2022-41702: Delta Electronics DIAEnergie
Published Oct 27, 2022
·Updated
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the InsertReg API.
Affected Software
3 affected components
Delta Electronics DIAEnergie versions prior to v1.9.01.002
Delta Electronics DIAEnergie versions prior to v1.9.02.001
Deltaww Diaenergie<1.9.01.002
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta Electronics DIAEnergieto a version that resolves this vulnerability.Fixed in v1.9.01.002
Event History
Oct 27, 2022
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-41702?
The severity of CVE-2022-41702 is high.
2
Which product is affected by CVE-2022-41702?
The affected product is DIAEnergie (versions prior to v1.9.01.002).
3
What is the vulnerability in CVE-2022-41702?
CVE-2022-41702 is a stored cross-site scripting vulnerability through the InsertReg API.
4
How can I fix CVE-2022-41702?
To fix CVE-2022-41702, update DIAEnergie to version 1.9.01.002 or higher.
5
Where can I find more information about CVE-2022-41702?
You can find more information about CVE-2022-41702 at https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-06.