Delta Electronics DIAEnergie SQL Injection in GetLatestDemandNode and GetDemandAnalysisData
Description
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in GetLatestDemandNode. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Delta Electronics DIAEnergie versions prior to 1.9 are vulnerable to blind SQL injection in GetLatestDemandNode, allowing remote attackers to retrieve/modify database content and execute system commands.
Vulnerability
A blind SQL injection vulnerability exists in the GetLatestDemandNode function of Delta Electronics DIAEnergie. Affected versions include all releases prior to version 1.9 [1]. The flaw is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).
Exploitation
The vulnerability can be exploited remotely over the network without authentication or user interaction. An attacker can inject arbitrary SQL queries into the vulnerable function, which processes user-supplied input without proper sanitization. The low attack complexity allows for easy exploitation [1].
Impact
Successful exploitation enables an attacker to retrieve and modify database contents, and execute system commands. This can lead to full compromise of confidentiality, integrity, and availability, with a CVSS v3 base score of 9.8 (Critical) [1].
Mitigation
Delta Electronics has released version 1.9 of DIAEnergie to address this vulnerability. Users are advised to update to version 1.9 or later. As of the advisory publication date (March 29, 2022), no workaround has been provided [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<1.8.02.004+ 1 more
- (no CPE)range: <1.8.02.004
- (no CPE)range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.cisa.gov/uscert/ics/advisories/icsa-22-081-01mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.