CVE-2022-41773: Delta Electronics DIAEnergie
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIACloud. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta Electronics DIAEnergie (CheckDIACloud)to a version that resolves this vulnerability.Fixed in v1.9.01.002
Event History
Frequently Asked Questions
What is CVE-2022-41773?
CVE-2022-41773 is a vulnerability in the DIAEnergie product (versions prior to v1.9.01.002) that allows a low-privileged authenticated attacker to perform SQL injection attacks.
What is the severity of CVE-2022-41773?
CVE-2022-41773 has a severity rating of 8.8 (High).
How does CVE-2022-41773 affect DIAEnergie?
CVE-2022-41773 affects DIAEnergie versions prior to v1.9.01.002 and allows for SQL injection attacks through CheckDIACloud.
How can an attacker exploit CVE-2022-41773?
An attacker with low privileges can exploit CVE-2022-41773 by injecting arbitrary SQL queries.
Is there a fix available for CVE-2022-41773?
Updating to DIAEnergie version v1.9.01.002 or later will fix the vulnerability CVE-2022-41773.