CVE-2024-43699: Delta Electronics DIAEnergie SQL Injection
Published Oct 3, 2024
·Updated
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AMRegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain records contained in the targeted product.
Affected Software
1 affected component
Deltaww Diaenergie<=1.10.01.008
Remediation
Information
Delta recommends users update to DIAEnergie v1.10.01.009. Users can request this version of DIAEnergie from Delta Electronics' regional sales or agents. https://www.deltaww.com/en-US/customerService
For more information on this issue, please see the Delta product cybersecurity advisory. https://www.deltaww.com/en-US/Cybersecurity_Advisory
Event History
Oct 3, 2024
CVE Published
via MITRE·10:28 PM
Data Sourced
via MITRE·10:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43699?
The severity of CVE-2024-43699 is critical as it allows an unauthenticated attacker to exploit SQL injection vulnerabilities.
2
How do I fix CVE-2024-43699?
To fix CVE-2024-43699, update to a version of Delta Electronics DIAEnergie that is above 1.10.01.008.
3
Which versions of DIAEnergie are affected by CVE-2024-43699?
DIAEnergie versions up to and including 1.10.01.008 are affected by CVE-2024-43699.
4
What type of attack does CVE-2024-43699 facilitate?
CVE-2024-43699 facilitates an SQL injection attack, allowing attackers to retrieve sensitive information.
5
Can CVE-2024-43699 be exploited remotely?
Yes, CVE-2024-43699 can be exploited remotely without authentication.