Blind SQL Injection Vulnerability in Delta Electronics DIAEnergie
CVE-2021-32983

9.8CRITICAL

Key Information:

Vendor

Deltaww

Vendor
CVE Published:
30 August 2021

What is CVE-2021-32983?

A Blind SQL injection vulnerability has been identified in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics' DIAEnergie application. This vulnerability arises from the inadequate validation of user-controlled input via the 'keyword' parameter before it is used in SQL queries. An unauthenticated remote attacker could exploit this flaw, enabling them to execute arbitrary commands within the context of NT SERVICE\MSSQLSERVER, thereby posing a significant security risk.

Affected Version(s)

Delta Electronics DIAEnergie DIAEnergie Version 1.7.5 and prior

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.