CVE-2022-43506: Delta Electronics DIAEnergie SQL Injection
Published Nov 17, 2022
·Updated
SQL Injection in
HandlerTagKID.ashx
in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
Affected Software
3 affected components
Delta Electronics DIAEnergie versions prior to v1.9.01.002
Delta Electronics DIAEnergie versions prior to v1.9.02.001
Deltaww Diaenergie<1.9.02.001
Event History
Nov 17, 2022
CVE Published
via MITRE·10:45 PM
Data Sourced
via MITRE·10:45 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-43506?
The severity of CVE-2022-43506 is high with a severity value of 8.8.
2
Which software versions are affected by CVE-2022-43506?
Delta Electronics DIAEnergie versions prior to v1.9.02.001 are affected by CVE-2022-43506.
3
What is the vulnerability type of CVE-2022-43506?
CVE-2022-43506 is a SQL Injection vulnerability.
4
How can an attacker exploit CVE-2022-43506?
An attacker can exploit CVE-2022-43506 by injecting SQL queries via the HandlerTag_KID.ashx file over the network.
5
Is there a fix available for CVE-2022-43506?
At the moment, there is no information about a fix available for CVE-2022-43506. It is recommended to follow the guidance provided in the referenced advisory.