CVE-2022-43447: Delta Electronics DIAEnergie SQL Injection
SQL Injection in
AMEBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta Electronics DIAEnergieto a version that resolves this vulnerability.Fixed in v1.9.02.001
Event History
Frequently Asked Questions
What is CVE-2022-43447?
CVE-2022-43447 is a SQL Injection vulnerability in Delta Electronics DIAEnergie versions prior to v1.9.02.001.
How does CVE-2022-43447 impact the security?
CVE-2022-43447 has a severity score of 8.8 (high) and allows an attacker to inject SQL queries via the network, potentially leading to unauthorized access or data manipulation.
What software is affected by CVE-2022-43447?
Delta Electronics DIAEnergie versions prior to v1.9.02.001 are affected by CVE-2022-43447.
How can I fix CVE-2022-43447?
To fix CVE-2022-43447, it is recommended to update Delta Electronics DIAEnergie to version v1.9.02.001 or later.
Where can I find more information about CVE-2022-43447?
You can find more information about CVE-2022-43447 on the CISA website: https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-06