Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Delta recommends users update to DIAEnergie v1.10.01.009. Users can request this version of DIAEnergie from Delta Electronics' regional sales or agents. https://www.deltaww.com/en-US/customerService For more information on this issue, please see the Delta product cybersecurity advisory. https://www.deltaww.com/en-US/Cybersecurity_Advisory
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39612 | Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the targeted product. |
Fri, 04 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Deltaww
Deltaww diaenergie |
|
| CPEs | cpe:2.3:a:deltaww:diaenergie:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Deltaww
Deltaww diaenergie |
|
| Metrics |
ssvc
|
Thu, 03 Oct 2024 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the targeted product. | |
| Title | Delta Electronics DIAEnergie SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-10-04T14:14:32.287Z
Reserved: 2024-10-01T17:18:54.590Z
Link: CVE-2024-42417
Updated: 2024-10-04T14:14:26.464Z
Status : Analyzed
Published: 2024-10-03T23:15:03.230
Modified: 2024-10-08T15:43:05.720
Link: CVE-2024-42417
No data.
OpenCVE Enrichment
No data.
EUVD