CVE-2024-42417

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 3, 2024
Updated: Oct 8, 2024
CWE ID 89

Summary

CVE-2024-42417 is a newly identified SQL injection vulnerability affecting Delta Electronics DIAEnergie. This issue lies in the script Handler_CFG.ashx, which can be exploited by authenticated attackers to cause delays in the targeted product. By injecting malicious SQL queries, they can manipulate the database and disrupt the normal functioning of the system. The impact of this vulnerability can result in performance degradation and potential denial-of-service conditions. It is essential for organizations using Delta Electronics DIAEnergie to apply the necessary patches or updates to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share