CVE-2022-41775: Delta Electronics DIAEnergie SQL Injection
SQL Injection in
HandlerCFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta Electronics DIAEnergie Handler_CFG.ashxto a version that resolves this vulnerability.Fixed in v1.9.02.001
Event History
Frequently Asked Questions
What is CVE-2022-41775?
CVE-2022-41775 is a SQL Injection vulnerability in Delta Electronics DIAEnergie versions prior to v1.9.02.001.
How does the SQL Injection vulnerability work in Delta Electronics DIAEnergie?
The vulnerability allows an attacker to inject SQL queries via Network.
What is the severity of CVE-2022-41775?
CVE-2022-41775 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2022-41775?
Delta Electronics DIAEnergie versions prior to v1.9.02.001 are affected by CVE-2022-41775.
How can I fix CVE-2022-41775?
To fix CVE-2022-41775, update Delta Electronics DIAEnergie to version v1.9.02.001 or later.
Where can I find more information about CVE-2022-41775?
More information about CVE-2022-41775 can be found at https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-06.