First published: Thu Oct 03 2024(Updated: )
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the targeted product.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
DIAEnergie | <=1.10.01.008 |
Delta recommends users update to DIAEnergie v1.10.01.009. Users can request this version of DIAEnergie from Delta Electronics' regional sales or agents. https://www.deltaww.com/en-US/customerService For more information on this issue, please see the Delta product cybersecurity advisory. https://www.deltaww.com/en-US/Cybersecurity_Advisory
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42417 is considered a high severity vulnerability due to its potential for exploitation by authenticated attackers.
To mitigate CVE-2024-42417, update the Delta Electronics DIAEnergie software to a version higher than 1.10.01.008.
CVE-2024-42417 is classified as an SQL injection vulnerability affecting the Handler_CFG.ashx script.
CVE-2024-42417 affects users of Delta Electronics DIAEnergie versions up to and including 1.10.01.008.
CVE-2024-42417 requires user authentication, which limits its exploitation to authenticated users on the system.