Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Delta recommends users update to DIAEnergie v1.10.01.009. Users can request this version of DIAEnergie from Delta Electronics' regional sales or agents. https://www.deltaww.com/en-US/customerService For more information on this issue, please see the Delta product cybersecurity advisory. https://www.deltaww.com/en-US/Cybersecurity_Advisory
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-40433 | Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain records contained in the targeted product. |
Fri, 04 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Deltaww
Deltaww diaenergie |
|
| CPEs | cpe:2.3:a:deltaww:diaenergie:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Deltaww
Deltaww diaenergie |
|
| Metrics |
ssvc
|
Thu, 03 Oct 2024 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain records contained in the targeted product. | |
| Title | Delta Electronics DIAEnergie SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-10-04T14:15:27.750Z
Reserved: 2024-10-01T17:18:54.603Z
Link: CVE-2024-43699
Updated: 2024-10-04T14:15:22.168Z
Status : Analyzed
Published: 2024-10-03T23:15:03.490
Modified: 2024-10-08T15:44:29.183
Link: CVE-2024-43699
No data.
OpenCVE Enrichment
No data.
EUVD