Blind SQL Injection in Delta Electronics DIAEnergie Software
CVE-2021-38391

9.8CRITICAL

Key Information:

Vendor

Deltaww

Vendor
CVE Published:
30 August 2021

What is CVE-2021-38391?

A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie, specifically in versions 1.7.5 and earlier. This vulnerability arises due to inadequate validation of user-controlled input in the 'type' parameter before it is utilized in SQL queries. As a result, an unauthenticated attacker can exploit this flaw to execute arbitrary SQL commands, potentially gaining access to sensitive information or executing code in the context of NT SERVICE\MSSQLSERVER, leading to significant security risks.

Affected Version(s)

Delta Electronics DIAEnergie DIAEnergie Version 1.7.5 and prior

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.