CVE-2024-4548: Delta Electronics DIAEnergie SQL Injection
Published May 6, 2024
·Updated
An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.
Affected Software
2 affected components
Delta Electronics DIAEnergie<1.10.1.8610
Deltaww Diaenergie<1.10.01.004
Event History
May 6, 2024
CVE Published
via MITRE·01:51 PM
Data Sourced
via MITRE·01:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-4548?
CVE-2024-4548 is classified as a critical SQL injection vulnerability.
2
How do I fix CVE-2024-4548?
To fix CVE-2024-4548, upgrade Delta Electronics DIAEnergie to version 1.10.1.8611 or later.
3
What types of attacks can be performed using CVE-2024-4548?
An unauthenticated remote attacker can exploit CVE-2024-4548 to perform SQL injection attacks.
4
What software is affected by CVE-2024-4548?
CVE-2024-4548 affects Delta Electronics DIAEnergie version 1.10.1.8610 and earlier.
5
Is authentication required to exploit CVE-2024-4548?
No, authentication is not required to exploit CVE-2024-4548.