Impact
The vulnerability is a SQL injection flaw in Delta DIAEnergie version 1.11.00.002, as described in the vendor advisory. An attacker who can inject malicious SQL statements can cause the application to execute arbitrary code on the underlying operating system. The excerpt in the CVE description explicitly states that this leads to remote code execution. The information does not indicate whether authentication or privileged access is required to exploit the flaw, so the exact attack vector or prerequisites remain unspecified.
Affected Systems
Delta DIAEnergie v1.11.00.002 is the only variant identified as vulnerable. Delta Technical Support recommends updating to version 1.11.00.022 or later. Users should verify the installed version against the vendor list of affected releases.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is considered high severity. EPSS data is not available, so the current likelihood of exploitation cannot be quantified. The issue is not listed in CISA’s KEV catalog, but the confirmed remote code execution impact warrants urgent remediation, especially in environments where the application accepts input from untrusted sources.
OpenCVE Enrichment