Skip to main content

Vendor/product archive

deltaww / diaenergie CVEs

Beta · best-effort

82 CVEs tagged to deltaww / diaenergie39 Critical, 35 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2024-43699

Published Oct 3, 2024

Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain records con…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-42417

Published Oct 3, 2024

Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the ta…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4549

Published May 6, 2024

A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4548

Published May 6, 2024

An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-4547

Published May 6, 2024

A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-34033

Published May 3, 2024

Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file na…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34032

Published May 3, 2024

Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to poten…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34031

Published May 3, 2024

Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potent…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28171

Published Mar 21, 2024

It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the origina…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28045

Published Mar 21, 2024

Improper neutralization of input within the affected product could lead to cross-site scripting.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25567

Published Mar 21, 2024

Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file sys…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28029

Published Mar 21, 2024

Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0822

Published Feb 17, 2023

The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass authorization and access privileg…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43506

Published Nov 17, 2022

SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43457

Published Nov 17, 2022

SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 82 CVEsPage 1 of 4