CVE-2022-43457: Delta Electronics DIAEnergie SQL Injection
SQL Injection in
HandlerPageKID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta Electronics DIAEnergieto a version that resolves this vulnerability.Fixed in v1.9.02.001 - Compensating control
Since Delta did not publicly release v1.9.01.002 or v1.9.02.001 in the material, contact Delta Electronics to receive the update packages for HandlerPage_KID.ashx SQL injection.
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2022-43457.
What is the severity of CVE-2022-43457?
The severity of CVE-2022-43457 is high with a CVSS score of 8.8.
Which software versions are affected by this vulnerability?
Delta Electronics DIAEnergie versions prior to v1.9.02.001 are affected by this vulnerability.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-89.
How can I fix CVE-2022-43457?
To fix CVE-2022-43457, it is recommended to upgrade Delta Electronics DIAEnergie to version v1.9.02.001 or later.