An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2024-13 |
|
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 27 Jun 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Deltaww
Deltaww diaenergie |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:deltaww:diaenergie:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Deltaww
Deltaww diaenergie |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-01T20:47:40.056Z
Reserved: 2024-05-06T13:35:43.319Z
Link: CVE-2024-4548
Updated: 2024-08-01T20:47:40.056Z
Status : Analyzed
Published: 2024-05-06T14:15:08.533
Modified: 2025-06-27T14:44:50.180
Link: CVE-2024-4548
No data.
OpenCVE Enrichment
No data.