Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-34601 Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.
Fixes

Solution

Delta Electronics recommends users update to DIAEnergie v1.10.01.004 to mitigate these vulnerabilities. Users can request this version of DIAEnergie from Delta Electronics' regional sales or agents.


Workaround

No workaround given by the vendor.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.01005}

epss

{'score': 0.00782}


Thu, 30 Jan 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Deltaww
Deltaww diaenergie
CPEs cpe:2.3:a:deltaww:diaenergie:1.10.00.005:*:*:*:*:*:*:*
Vendors & Products Deltaww
Deltaww diaenergie

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-12T20:08:42.943Z

Reserved: 2024-04-29T17:56:18.036Z

Link: CVE-2024-34032

cve-icon Vulnrichment

Updated: 2024-08-02T02:42:59.827Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-03T01:15:48.197

Modified: 2025-01-30T14:31:00.057

Link: CVE-2024-34032

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.