Impact
The vulnerability in DeltaWww DIAEnergie is a SQL injection flaw that can be exploited to execute arbitrary code on the host. An attacker can craft malicious input to the application’s interface on version 1.11.00.002; the injected SQL commands can culminate in remote code execution, giving full control of the underlying system, exposing sensitive data, and compromising integrity and availability. The flaw is identified as CWE‑89, the standard designation for SQL injection weaknesses. No other exploitation mechanisms are described in the advisory.
Affected Systems
Only versions of DeltaWww DIAEnergie that include the vulnerable code are affected. Version 1.11.00.002 has been confirmed to contain the flaw. The vendor advises upgrading to 1.11.00.022 or any later release to remove the vulnerability. All other versions not listed are considered unaffected unless otherwise specified by the vendor.
Risk and Exploitability
With a CVSS score of 8.8 the issue registers as high severity. No EPSS score is published, and the vulnerability is not listed in CISA’s KEV catalogue. Nevertheless, the potential for remote code execution via SQL injection makes it a high‑risk exposure with a plausibly significant exploitation chance. An attacker can exploit the flaw remotely by sending crafted input to the vulnerable interface of a reachable system.
OpenCVE Enrichment