Impact
Delta DIAEnergie v1.11.00.002 contains a SQL Injection flaw that can be exploited by supplying crafted input to vulnerable database queries. The injection allows an attacker to execute arbitrary SQL statements, which can be leveraged to achieve remote code execution. This enables full compromise of the affected system, compromising confidentiality, integrity, and availability of data and services.
Affected Systems
Affected systems are instances of Delta DIAEnergie version 1.11.00.002. No other product versions are known to be impacted according to the vendor's CNAs. The flaw resides in the database interaction layer of this specific release.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is classified as high severity. The EPSS score is not available, and the flaw is not listed in CISA's KEV catalog, indicating no confirmed active exploitation as of this analysis. Nonetheless, because the flaw is remote and allows code execution, the likely attack vector is over an exposed web interface or application layer and can be triggered without local privileges. An attacker with network access to the application could submit malicious input and gain remote execution capability.
OpenCVE Enrichment