PT-2024-31657 · Delta Electronics · Diaenergie

Published

2024-05-06

·

Updated

2025-06-27

·

CVE-2024-4548

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Delta Electronics DIAEnergie versions 1.10.1.8610 and prior
Description: A vulnerability exists when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQL injection via the fourth field.
Recommendations: For Delta Electronics DIAEnergie versions 1.10.1.8610 and prior, consider disabling the processing of 'RecalculateHDMWYC' messages in CEBC.exe until a patch is available. Restrict access to the fourth field of the 'RecalculateHDMWYC' message to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-4548

Affected Products

Diaenergie