Diaenergie
by Deltaww
CVEs (46)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-32983 | Cri | 0.64 | 9.8 | 0.04 | Aug 30, 2021 | A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part… | ||
| CVE-2021-32967 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with administrative privileges. | ||
| CVE-2024-25574 | Hig | 0.58 | 8.8 | 0.09 | Apr 1, 2024 | SQL injection vulnerability exists in GetDIAE_usListParameters. | ||
| CVE-2024-28040 | Hig | 0.58 | 8.8 | 0.08 | Mar 21, 2024 | SQL injection vulnerability exists in GetDIAE_astListParameters. | ||
| CVE-2022-43452 | Hig | 0.58 | 8.8 | 0.08 | Nov 17, 2022 | SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network | ||
| CVE-2024-34033 | Hig | 0.57 | 8.8 | 0.01 | May 3, 2024 | Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.… | ||
| CVE-2024-34031 | Hig | 0.57 | 8.8 | 0.01 | May 3, 2024 | Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed. | ||
| CVE-2024-28029 | Hig | 0.57 | 8.8 | 0.01 | Mar 21, 2024 | Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality. | ||
| CVE-2022-43457 | Hig | 0.57 | 8.8 | 0.01 | Nov 17, 2022 | SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network | ||
| CVE-2022-41702 | Hig | 0.57 | 8.7 | 0.11 | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the InsertReg API. | ||
| CVE-2022-41555 | Hig | 0.57 | 8.7 | 0.11 | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API. | ||
| CVE-2024-25567 | Hig | 0.53 | 8.1 | 0.01 | Mar 21, 2024 | Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file system, then the original file will be overwritten. | ||
| CVE-2022-1098 | Hig | 0.51 | 7.8 | 0.00 | Apr 1, 2022 | Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default Permissions vulnerability of 4.2.2 above, this makes it possible for an attacker to escalate privileges | ||
| CVE-2022-26839 | Hig | 0.51 | 7.8 | 0.00 | Mar 29, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files. | ||
| CVE-2024-4549 | Hig | 0.49 | 7.5 | 0.01 | May 6, 2024 | A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system. | ||
| CVE-2021-44471 | Hig | 0.49 | 7.5 | 0.01 | Dec 22, 2021 | DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “name” of the script “DIAE_HandlerAlarmGroup.ashx”. | ||
| CVE-2022-0988 | Hig | 0.46 | 7.1 | 0.01 | Mar 25, 2022 | Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product. | ||
| CVE-2021-31558 | Med | 0.43 | 6.5 | 0.11 | Dec 22, 2021 | DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”. | ||
| CVE-2025-57703 | Med | 0.40 | 6.1 | 0.00 | Aug 18, 2025 | DIAEnergie - Reflected Cross-site Scripting | ||
| CVE-2025-57702 | Med | 0.40 | 6.1 | 0.00 | Aug 18, 2025 | DIAEnergie - Reflected Cross-site Scripting |
- risk 0.64cvss 9.8epss 0.04
A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part…
- risk 0.64cvss 9.8epss 0.01
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with administrative privileges.
- risk 0.58cvss 8.8epss 0.09
SQL injection vulnerability exists in GetDIAE_usListParameters.
- risk 0.58cvss 8.8epss 0.08
SQL injection vulnerability exists in GetDIAE_astListParameters.
- risk 0.58cvss 8.8epss 0.08
SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
- risk 0.57cvss 8.8epss 0.01
Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.…
- risk 0.57cvss 8.8epss 0.01
Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.
- risk 0.57cvss 8.8epss 0.01
Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.
- risk 0.57cvss 8.8epss 0.01
SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
- risk 0.57cvss 8.7epss 0.11
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the InsertReg API.
- risk 0.57cvss 8.7epss 0.11
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API.
- risk 0.53cvss 8.1epss 0.01
Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file system, then the original file will be overwritten.
- risk 0.51cvss 7.8epss 0.00
Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default Permissions vulnerability of 4.2.2 above, this makes it possible for an attacker to escalate privileges
- risk 0.51cvss 7.8epss 0.00
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files.
- risk 0.49cvss 7.5epss 0.01
A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.
- risk 0.49cvss 7.5epss 0.01
DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “name” of the script “DIAE_HandlerAlarmGroup.ashx”.
- risk 0.46cvss 7.1epss 0.01
Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.
- risk 0.43cvss 6.5epss 0.11
DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”.
- risk 0.40cvss 6.1epss 0.00
DIAEnergie - Reflected Cross-site Scripting
- risk 0.40cvss 6.1epss 0.00
DIAEnergie - Reflected Cross-site Scripting
Page 2 of 3