First published: Thu Nov 17 2022(Updated: )
SQL Injection in AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Diaenergie | <1.9.02.001 | |
Delta Electronics DIAEnergie versions prior to v1.9.01.002 | ||
Delta Electronics DIAEnergie versions prior to v1.9.02.001 |
Delta did not publicly release v1.9.01.002 or v1.9.02.001, which addresses these vulnerabilities. Users are encouraged to contact Delta to receive these updates.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43447 is a SQL Injection vulnerability in Delta Electronics DIAEnergie versions prior to v1.9.02.001.
CVE-2022-43447 has a severity score of 8.8 (high) and allows an attacker to inject SQL queries via the network, potentially leading to unauthorized access or data manipulation.
Delta Electronics DIAEnergie versions prior to v1.9.02.001 are affected by CVE-2022-43447.
To fix CVE-2022-43447, it is recommended to update Delta Electronics DIAEnergie to version v1.9.02.001 or later.
You can find more information about CVE-2022-43447 on the CISA website: https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-06