Unrated severityNVD Advisory· Published Aug 30, 2021· Updated Aug 3, 2024
CVE-2021-32983
CVE-2021-32983
Description
A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Delta Electronics/DIAEnergiedescription
- Range: <=1.7.5
Patches
Vulnerability mechanics
References
1- us-cert.cisa.gov/ics/advisories/icsa-21-238-03mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.