ID

VAR-202210-1862


CVE

CVE-2022-41773


TITLE

Delta Electronics, INC.  of  DIAEnergie  In  SQL  Injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2022-019796

DESCRIPTION

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIACloud. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries. Delta Electronics, INC. of DIAEnergie for, SQL There is an injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.62

sources: NVD: CVE-2022-41773 // JVNDB: JVNDB-2022-019796

AFFECTED PRODUCTS

vendor:deltawwmodel:diaenergiescope:ltversion:1.9.01.002

Trust: 1.0

vendor:deltamodel:diaenergiescope: - version: -

Trust: 0.8

vendor:deltamodel:diaenergiescope:eqversion:1.9.01.002

Trust: 0.8

vendor:deltamodel:diaenergiescope:eqversion: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-019796 // NVD: CVE-2022-41773

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2022-41773
value: HIGH

Trust: 1.8

ics-cert@hq.dhs.gov: CVE-2022-41773
value: HIGH

Trust: 1.0

CNNVD: CNNVD-202210-2160
value: HIGH

Trust: 0.6

NVD:
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 2.0

NVD: CVE-2022-41773
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-019796 // NVD: CVE-2022-41773 // NVD: CVE-2022-41773 // CNNVD: CNNVD-202210-2160

PROBLEMTYPE DATA

problemtype:CWE-89

Trust: 1.0

problemtype:SQL injection (CWE-89) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-019796 // NVD: CVE-2022-41773

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202210-2160

TYPE

SQL injection

Trust: 0.6

sources: CNNVD: CNNVD-202210-2160

CONFIGURATIONS

sources: NVD: CVE-2022-41773

EXTERNAL IDS

db:NVDid:CVE-2022-41773

Trust: 3.2

db:ICS CERTid:ICSA-22-298-06

Trust: 2.4

db:JVNid:JVNVU91874962

Trust: 0.8

db:JVNDBid:JVNDB-2022-019796

Trust: 0.8

db:AUSCERTid:ESB-2022.5371

Trust: 0.6

db:CNNVDid:CNNVD-202210-2160

Trust: 0.6

sources: JVNDB: JVNDB-2022-019796 // NVD: CVE-2022-41773 // CNNVD: CNNVD-202210-2160

REFERENCES

url:https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-06

Trust: 2.4

url:https://jvn.jp/vu/jvnvu91874962/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2022-41773

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-41773/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.5371

Trust: 0.6

sources: JVNDB: JVNDB-2022-019796 // NVD: CVE-2022-41773 // CNNVD: CNNVD-202210-2160

SOURCES

db:JVNDBid:JVNDB-2022-019796
db:NVDid:CVE-2022-41773
db:CNNVDid:CNNVD-202210-2160

LAST UPDATE DATE

2023-12-18T11:55:26.831000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2022-019796date:2023-10-27T08:12:00
db:NVDid:CVE-2022-41773date:2022-10-28T18:32:47.430
db:CNNVDid:CNNVD-202210-2160date:2022-10-31T00:00:00

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2022-019796date:2023-10-27T00:00:00
db:NVDid:CVE-2022-41773date:2022-10-27T21:15:16.593
db:CNNVDid:CNNVD-202210-2160date:2022-10-26T00:00:00