CVE-2024-42417: Delta Electronics DIAEnergie SQL Injection
Published Oct 3, 2024
·Updated
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script HandlerCFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the targeted product.
Affected Software
1 affected component
Deltaww Diaenergie<=1.10.01.008
Remediation
Information
Delta recommends users update to DIAEnergie v1.10.01.009. Users can request this version of DIAEnergie from Delta Electronics' regional sales or agents. https://www.deltaww.com/en-US/customerService
For more information on this issue, please see the Delta product cybersecurity advisory. https://www.deltaww.com/en-US/Cybersecurity_Advisory
Event History
Oct 3, 2024
CVE Published
via MITRE·10:32 PM
Data Sourced
via MITRE·10:32 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-42417?
CVE-2024-42417 is considered a high severity vulnerability due to its potential for exploitation by authenticated attackers.
2
How do I fix CVE-2024-42417?
To mitigate CVE-2024-42417, update the Delta Electronics DIAEnergie software to a version higher than 1.10.01.008.
3
What type of vulnerability is CVE-2024-42417?
CVE-2024-42417 is classified as an SQL injection vulnerability affecting the Handler_CFG.ashx script.
4
Who is affected by CVE-2024-42417?
CVE-2024-42417 affects users of Delta Electronics DIAEnergie versions up to and including 1.10.01.008.
5
Can CVE-2024-42417 be exploited remotely?
CVE-2024-42417 requires user authentication, which limits its exploitation to authenticated users on the system.