Blind SQL Injection Vulnerability in Delta Electronics DIAEnergie Software
CVE-2021-38390

9.8CRITICAL

Key Information:

Vendor

Deltaww

Vendor
CVE Published:
30 August 2021

What is CVE-2021-38390?

A Blind SQL Injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics' DIAEnergie software. The software fails to adequately validate user-input values through the 'egyid' parameter before incorporating them into SQL queries, making it susceptible to exploitation. This allows a remote, unauthenticated attacker to execute arbitrary SQL commands, potentially leading to unauthorized access and manipulation of sensitive data in the context of the NT SERVICE\MSSQLSERVER account.

Affected Version(s)

Delta Electronics DIAEnergie DIAEnergie Version 1.7.5 and prior

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.