Delta Electronics DIAEnergie SQL Injection
Published May 6, 2024
9.8
CRITICALCVSS 3.1
EPSS 29.43%
Description
An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.
Affected products
-
Affected
- ≥ 0, ≤ 1.10.1.8610
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Delta Electronics | DIAEnergie | unaffected | Affected
|
- < 1.10.01.004
-
Affected
- ≥ 0, ≤ 1.10.1.8610
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Deltaww | Diaenergie | unknown | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-44160 Advisory
- https://www.tenable.com/security/research/tra-2024-13 ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-44160 | Advisory | |
| https://www.tenable.com/security/research/tra-2024-13 | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data