First published: Thu Nov 17 2022(Updated: )
SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Diaenergie | <1.9.02.001 | |
Delta Electronics DIAEnergie versions prior to v1.9.01.002 | ||
Delta Electronics DIAEnergie versions prior to v1.9.02.001 |
Delta did not publicly release v1.9.01.002 or v1.9.02.001, which addresses these vulnerabilities. Users are encouraged to contact Delta to receive these updates.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43452 is a vulnerability in Delta Electronics DIAEnergie that allows an attacker to inject SQL queries via Network.
CVE-2022-43452 has a severity rating of 8.8 (high).
CVE-2022-43452 affects Delta Electronics DIAEnergie versions prior to v1.9.02.001.
An attacker can exploit CVE-2022-43452 by injecting SQL queries via Network.
Yes, updating Delta Electronics DIAEnergie to version v1.9.02.001 or higher fixes CVE-2022-43452.