CVE-2022-43775: SQL Injection
The HICTLoop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43775?
The severity of CVE-2022-43775 is critical with a CVSS score of 9.8.
What is the affected software for CVE-2022-43775?
The affected software for CVE-2022-43775 is Delta Electronics DIAEnergy v1.9.
How does the SQL Injection flaw in CVE-2022-43775 work?
The SQL Injection flaw in CVE-2022-43775 allows an attacker to execute arbitrary SQL queries, potentially gaining unauthorized access or control over the affected system.
Can an attacker exploit the SQL Injection flaw remotely?
Yes, an attacker can exploit the SQL Injection flaw in CVE-2022-43775 remotely, allowing them to gain code execution on a remote system.
Is there a fix available for CVE-2022-43775?
At the moment, there is no known fix or patch available for CVE-2022-43775. It is recommended to apply mitigations or contact the vendor for further guidance.