Beveiligingsadvies

CVE-2024-4548

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-05-06 13:51:07
Laatst bijgewerkt 2024-08-01 20:47:40
Toegewezen door tenable
CVSS-score 9.8
Status PUBLISHED

Beschrijving

An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.