First published: Thu Nov 17 2022(Updated: )
SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Diaenergie | <1.9.02.001 | |
Delta Electronics DIAEnergie versions prior to v1.9.01.002 | ||
Delta Electronics DIAEnergie versions prior to v1.9.02.001 | ||
<1.9.02.001 |
Delta did not publicly release v1.9.01.002 or v1.9.02.001, which addresses these vulnerabilities. Users are encouraged to contact Delta to receive these updates.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-43506 is high with a severity value of 8.8.
Delta Electronics DIAEnergie versions prior to v1.9.02.001 are affected by CVE-2022-43506.
CVE-2022-43506 is a SQL Injection vulnerability.
An attacker can exploit CVE-2022-43506 by injecting SQL queries via the HandlerTag_KID.ashx file over the network.
At the moment, there is no information about a fix available for CVE-2022-43506. It is recommended to follow the guidance provided in the referenced advisory.